Impact
The vulnerability in Dell Container Storage Modules allows a low-privileged remote attacker to cause sensitive data to be written to log files, resulting in information disclosure. This is an insertion of sensitive information into logs, classified as CWE-532, where confidential data intended for system use is exposed through publicly accessible log files.
Affected Systems
Affected are Dell Container Storage Modules running versions prior to 1.18.0. Any deployment of these older versions that remains reachable over the network is potentially vulnerable to exploitation.
Risk and Exploitability
The flaw carries a CVSS score of 6.5, indicating moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Remote exploitation requires low-level access to the module, likely through existing management interfaces. Once executed, an attacker can read the exposed log files and acquire confidential information.
OpenCVE Enrichment