Impact
Dell Container Storage Modules prior to version 1.18.0 embed hard‑coded credentials in their authorization component. An unauthenticated network user can exploit this flaw to authenticate as an administrator, thereby gaining full control of the system. The vulnerability directly undermines confidentiality and integrity and allows arbitrary privileged actions, including the execution of commands that could compromise the entire storage environment.
Affected Systems
Dell Container Storage Modules (CSM) versions earlier than 1.18.0 are affected. The flaw resides in the CSM authorization layer and has not been addressed in any prior releases.
Risk and Exploitability
The CVSS score of 9.8 denotes a critical risk level. EPSS data is unavailable, but the lack of a KEV listing suggests no widespread exploitation has been reported yet. Based on the description, it is inferred that an attacker only needs remote, unauthenticated access to the CSM interface to exploit the hard‑coded credentials and elevate privileges. If successful, the attacker can assume administrator rights, compromising the entire container storage environment.
OpenCVE Enrichment