Impact
The vulnerability is a missing‑authorization flaw identified as CWE‑862. It allows an attacker who has access to a mapped host to read from or write to LUNs that the host is not authorized to use, bypassing per‑initiator LUN access controls. This results in unauthorized data exposure, tampering, and potential disruption of services, thereby compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects multiple Dell PowerStore models, including the 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T and 9200T series. No specific firmware or model version is listed; any system with a mapped host that connects to LUNs is potentially susceptible.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS data is unavailable and the exposure is not listed in the CISA KEV catalog. Attacks would likely require the attacker to have network or host access to a mapped host that communicates with the PowerStore array. With such access, the attacker can exploit the missing authorization to bypass LUN permissions and perform unauthorized read/write operations.
OpenCVE Enrichment