Description
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Published: 2026-10-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Information disclosure
Action: Patch
AI Analysis

Impact

The vulnerability in Dell Container Storage Modules allows a low-privileged remote attacker to cause sensitive data to be written to log files, resulting in information disclosure. This is an insertion of sensitive information into logs, classified as CWE-532, where confidential data intended for system use is exposed through publicly accessible log files.

Affected Systems

Affected are Dell Container Storage Modules running versions prior to 1.18.0. Any deployment of these older versions that remains reachable over the network is potentially vulnerable to exploitation.

Risk and Exploitability

The flaw carries a CVSS score of 6.5, indicating moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Remote exploitation requires low-level access to the module, likely through existing management interfaces. Once executed, an attacker can read the exposed log files and acquire confidential information.

Generated by OpenCVE AI on October 6, 2026 at 18:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell Container Storage Modules security update to version 1.18.0 or later, which removes the log‑injection flaw.
  • Reconfigure logging or adjust log verbosity settings so that sensitive or confidential fields are omitted or masked before being written to persistent logs.
  • Continuously monitor and audit log files for accidental disclosure of sensitive information and enforce strict access controls on log repositories.

Generated by OpenCVE AI on October 6, 2026 at 18:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Title Sensitive Information Leakage via Log File in Dell Container Storage Modules

Tue, 06 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Description Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-10-06T16:27:39.369Z

Reserved: 2026-07-17T17:05:09.170Z

Link: CVE-2026-63689

cve-icon Vulnrichment

Updated: 2026-10-06T16:27:30.485Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T16:17:08.937

Modified: 2026-10-06T19:58:37.060

Link: CVE-2026-63689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:15:04Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File