Description
Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution and Denial of service.
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer copy without size checking in the NFS/RPC service of Dell PowerStore systems allows an unauthenticated attacker with network access to overwrite memory, potentially leading to arbitrary command execution or service disruption. The type of weakness is a classic buffer overflow (CWE‑120). The impact is the compromise of confidentiality, integrity, and availability of the affected PowerStore appliance.

Affected Systems

Dell PowerStore models 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, 9200T are affected according to the vendor advisory. Exact firmware or software release information is not specified, so all current releases of these models are potentially vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 8.1, indicating high severity. EPSS is not available, so exploitation likelihood is uncertain, and it is not yet listed in the CISA KEV catalog. The likely attack vector is remote over the network, requiring no authentication. An attacker can trigger the buffer overwrite by sending a crafted NFS/RPC request, after which they may execute arbitrary code or crash the service.

Generated by OpenCVE AI on August 18, 2026 at 19:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the Dell PowerStore security update published on 2026‑330 as described in the Dell advisory
  • Restrict inbound NFS/RPC traffic to trusted IP ranges
  • Monitor for anomalous RPC activity

Generated by OpenCVE AI on August 18, 2026 at 19:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Remote Command Execution via Buffer Overflow in Dell PowerStore NFS/RPC Service

Tue, 18 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t

Tue, 18 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution and Denial of service.
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-19T03:56:06.548Z

Reserved: 2026-08-04T11:16:10.499Z

Link: CVE-2026-70415

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T17:17:01.973

Modified: 2026-08-19T04:17:37.820

Link: CVE-2026-70415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T20:00:04Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')