Description
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Published: 2026-08-17
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell ObjectScale prior to 4.3.0.1 contains a CWE‑532 weakness—Insertion of Sensitive Information into Log File—in svc_tools. A low‑privileged attacker with local access can trigger the application to write confidential data, such as credentials or secrets, directly to system logs. The disclosure of this information allows attackers to compromise confidentiality by retrieving secrets that should remain protected.

Affected Systems

Dell ObjectScale versions earlier than 4.3.0.1 are affected. No specific patch versions are listed beyond 4.3.0.1, so any release with a version number less than 4.3.0.1 is at risk.

Risk and Exploitability

The CVSS score of 5.5 places the vulnerability in the medium range in terms of confidentiality impact. The EPSS score is not available and Dell ObjectScale is not listed in the CISA KEV catalog, indicating no known active exploits as of this analysis. The likely attack vector is local: an attacker who has low‑privileged access to the system and the svc_tools directory can exploit the flaw. While the risk is moderate, the potential leakage of sensitive data justifies prompt remediation.

Generated by OpenCVE AI on August 17, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell 2026‑328 security update to upgrade Dell ObjectScale to version 4.3.0.1 or later.
  • Revoke or limit local accounts that have low privileges to access the svc_tools directory and its log files.
  • Audit existing log files for accidental leakage of sensitive data and securely purge or store the records.
  • Implement monitoring to detect anomalous logging behavior that could indicate exploitation.

Generated by OpenCVE AI on August 17, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*

Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure via Insertion of Sensitive Data into Logs in Dell ObjectScale svc_tools

Mon, 17 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell objectscale
Vendors & Products Dell
Dell objectscale

Mon, 17 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Objectscale
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-17T17:57:17.000Z

Reserved: 2026-07-07T17:04:34.467Z

Link: CVE-2026-59911

cve-icon Vulnrichment

Updated: 2026-08-17T17:56:27.041Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-17T14:20:21.770

Modified: 2026-08-19T01:09:48.853

Link: CVE-2026-59911

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T16:30:06Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File