Impact
Dell PowerStore SDNAS contains a buffer copy without checking the size of input in its NFS/RPC service. This flaw enables an unauthenticated attacker with remote access to overwrite memory, potentially resulting in command execution or service disruption. The weakness is a classic buffer overflow (CWE‑120). The impact includes loss of confidentiality, integrity, and availability of the affected PowerStore appliance.
Affected Systems
Dell PowerStore models 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, 9200T are affected according to the vendor advisory. Exact firmware or software release information is not specified, so all current releases of these models are potentially vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, indicating high severity. The EPSS score is < 1%, reflecting a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over the network and requires no authentication. An attacker can trigger the buffer overwrite by sending a crafted NFS/RPC request, after which they may execute arbitrary code or crash the service.
OpenCVE Enrichment