Description
Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for Remote Code execution.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerStore’s SMB/CIFS implementation contains an out‑of‑bounds write flaw that can be triggered by a specially crafted SMB packet. The vulnerability allows an unauthenticated remote attacker to corrupt memory, potentially causing a crash or enabling the delivery of malicious code. If the device is configured to restart automatically, the crash may become persistent, resulting in a denial of service. The type of weakness corresponds to CWE‑787, an out‑of‑bounds write.

Affected Systems

The flaw affects all Dell PowerStore storage arrays in the 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T lines. No specific firmware revisions are listed, so any component running the SMB/CIFS services on these models is assumed vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 9.8, indicating critical severity. EPSS data is unavailable, and it is not yet listed in CISA’s KEV catalog. Because the attack requires no prior authentication and can be performed over the network, the attack vector is remote. An attacker can send crafted SMB traffic from outside the trusted network, trigger a crash, and, with a more advanced payload, potentially achieve remote code execution.

Generated by OpenCVE AI on August 18, 2026 at 18:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerStore security update published in the Dell Knowledge Base at https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities
  • Restrict SMB/CIFS traffic to trusted networks or disable the SMB service if it is not required for operations
  • Configure firewalls and network segmentation to block unauthenticated or suspicious SMB connections and monitor logs for anomalous SMB activity

Generated by OpenCVE AI on August 18, 2026 at 18:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t

Tue, 18 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Dell PowerStore Out‑of‑Bounds Write in SMB/CIFS Leading to Possible Remote Code Execution

Tue, 18 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for Remote Code execution.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T03:56:05.259Z

Reserved: 2026-07-29T11:04:32.678Z

Link: CVE-2026-67271

cve-icon Vulnrichment

Updated: 2026-08-18T19:09:46.375Z

cve-icon NVD

Status : Received

Published: 2026-08-18T17:17:00.973

Modified: 2026-08-19T04:17:37.670

Link: CVE-2026-67271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T19:45:03Z

Weaknesses