Impact
Dell PowerStore suffers from a command injection flaw that permits an authenticated user with limited privileges to inject and run arbitrary commands. The flaw can raise the privileges of the injected command to root, enabling the attacker to modify or delete data, disrupt services, and compromise the entire system’s integrity.
Affected Systems
The vulnerability affects multiple Dell PowerStore models, including 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T. All devices operating versions listed in the Dell support KB reference are potentially impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity RCE risk. While the EPSS score is not available, the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker must first be authenticated and have limited user rights; from that position, they can trigger the injection, execute arbitrary code, and obtain root-level control. The absence of publicly documented exploit code does not diminish the theoretical exploitability, especially in environments with permissive local access.
OpenCVE Enrichment