Description
Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution and denial of service.
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerStore SDNAS contains a buffer copy without checking the size of input in its NFS/RPC service. This flaw enables an unauthenticated attacker with remote access to overwrite memory, potentially resulting in command execution or service disruption. The weakness is a classic buffer overflow (CWE‑120). The impact includes loss of confidentiality, integrity, and availability of the affected PowerStore appliance.

Affected Systems

Dell PowerStore models 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, 9200T are affected according to the vendor advisory. Exact firmware or software release information is not specified, so all current releases of these models are potentially vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 8.1, indicating high severity. The EPSS score is < 1%, reflecting a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over the network and requires no authentication. An attacker can trigger the buffer overwrite by sending a crafted NFS/RPC request, after which they may execute arbitrary code or crash the service.

Generated by OpenCVE AI on August 31, 2026 at 07:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the Dell PowerStore security update published on 2026‑330 as described in the Dell advisory
  • Restrict inbound NFS/RPC traffic to trusted IP ranges
  • Monitor for anomalous RPC activity

Generated by OpenCVE AI on August 31, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Remote Command Execution via Buffer Overflow in Dell PowerStore NFS/RPC Service

Mon, 31 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution and Denial of service. Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution and denial of service.

Tue, 18 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Remote Command Execution via Buffer Overflow in Dell PowerStore NFS/RPC Service

Tue, 18 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t

Tue, 18 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution and Denial of service.
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-31T06:04:14.301Z

Reserved: 2026-08-04T11:16:10.499Z

Link: CVE-2026-70415

cve-icon Vulnrichment

Updated: 2026-08-20T18:36:51.435Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T17:17:01.973

Modified: 2026-08-31T07:17:45.537

Link: CVE-2026-70415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T07:30:18Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')