Impact
A Protection Mechanism Failure in Dell PowerStore allows an authenticated user with limited privileges to bypass access restrictions and gain higher privileges, effectively letting an attacker redirect management paths and control storage resources. The flaw is classified as CWE‑693, indicating that proper access controls were not enforced.
Affected Systems
Affected systems include Dell PowerStore models 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T. No specific version details are provided; the vulnerability applies to all currently supported releases at the time of the advisory.
Risk and Exploitability
The CVSS score of 8.8 signifies high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. An attacker requires valid credentials with at least limited access; once logged in, the flaw can be used to elevate privileges without additional attack vectors. The combination of a high score and lack of widespread exploitation mitigations imposes a significant risk on environments deploying the affected PowerStore appliances.
OpenCVE Enrichment