Impact
Dell Container Storage Modules before version 1.18.0 are affected by a missing authentication flaw in the TenantService gRPC endpoint. The vulnerability allows an attacker with network proximity to create arbitrary tenant entities, inject cross‑tenant roles, and alter storage access control flags without any credentials, giving them unauthorized control over the storage platform.
Affected Systems
The affected products are Dell Container Storage Modules (CSM) running version 1.17.x and earlier.
Risk and Exploitability
The flaw scores a 7.1 on CVSS, indicating a high impact. EPSS is not available, but the vulnerability is not listed in CISA KEV. The attack vector is likely an unauthenticated adversary on an adjacent or otherwise trusted local network that can reach the gRPC service, making exploitation feasible without initial compromise.
OpenCVE Enrichment