Description
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths.
Published: 2026-09-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized write access to arbitrary filesystem paths
Action: Immediate Patch
AI Analysis

Impact

Dell PowerStore is vulnerable to a protection mechanism failure (CWE-693) that lets an authenticated user, even with limited privileges, write attacker‑controlled content to arbitrary paths on the appliance. This flaw can compromise data integrity and potentially lead to further system tampering, as malicious files could be placed in critical configuration directories or system libraries.

Affected Systems

Affected are numerous Dell PowerStore models including 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T, across both the 1000T/1200T/3000T high‑capacity series and the 3200Q/T, 5200Q/T, 7000T, 9000T, and 9200T storage arrays.

Risk and Exploitability

The CVSS score of 8.8 highlights high severity; the EPSS score is not available, so exploitation probability is unknown, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector involves a legitimate user account with access to the PowerStore management interface; the user may upload or configure data that the appliance treats as arbitrary filesystem writes. Once triggered, the attacker can overwrite or create files throughout the appliance’s filesystem, providing a vector for persistence, privilege escalation, or denial of service.

Generated by OpenCVE AI on September 1, 2026 at 16:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerStore Security Update (DSA‑2026‑330) to all affected PowerStore models immediately
  • Remove or restrict any user accounts that have unnecessary write permissions on the appliance’s filesystem
  • Review and enforce the principle of least privilege for all management and storage service accounts

Generated by OpenCVE AI on September 1, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Privileges Allow Arbitrary File Write in Dell PowerStore
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths.
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-02T03:55:33.876Z

Reserved: 2026-08-25T12:04:33.629Z

Link: CVE-2026-79683

cve-icon Vulnrichment

Updated: 2026-09-01T15:05:43.754Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T13:19:59.457

Modified: 2026-09-02T04:18:02.070

Link: CVE-2026-79683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T16:30:17Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure