Impact
Dell PowerStore is vulnerable to a protection mechanism failure (CWE-693) that lets an authenticated user, even with limited privileges, write attacker‑controlled content to arbitrary paths on the appliance. This flaw can compromise data integrity and potentially lead to further system tampering, as malicious files could be placed in critical configuration directories or system libraries.
Affected Systems
Affected are numerous Dell PowerStore models including 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T, across both the 1000T/1200T/3000T high‑capacity series and the 3200Q/T, 5200Q/T, 7000T, 9000T, and 9200T storage arrays.
Risk and Exploitability
The CVSS score of 8.8 highlights high severity; the EPSS score is not available, so exploitation probability is unknown, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector involves a legitimate user account with access to the PowerStore management interface; the user may upload or configure data that the appliance treats as arbitrary filesystem writes. Once triggered, the attacker can overwrite or create files throughout the appliance’s filesystem, providing a vector for persistence, privilege escalation, or denial of service.
OpenCVE Enrichment