Impact
Dell PowerStore storage arrays contain an Argument Injection flaw that allows an authenticated user with limited privileges to inject arbitrary command-line arguments. This flaw enables the attacker to bypass normal authorization controls and retrieve sensitive system data normally restricted to privileged users. The resulting impact is the disclosure of confidential system information, potentially exposing configuration, management, and stored data.
Affected Systems
Affected systems include Dell PowerStore models such as 1000T, 1200T, 3000T, 3200Q, 3200T, 500T, 5200Q, 5200T, 5000T, 7000T, 9000T, and 9200T. All listed variants are subject to the Argument Injection vulnerability and should be evaluated for the presence of the issued security update.
Risk and Exploitability
The CVSS score of 6.5 places this flaw in the moderate seriousness bracket, and the lack of an EPSS value indicates that current exploitation probability data is unavailable. Since the vulnerability requires prior authenticated access with limited privileges, it is most likely to be leveraged by insiders or compromised accounts rather than by remote unauthenticated attackers. The flaw is not present in the CISA KEV catalog, suggesting no known widespread exploitation, but its moderate severity and potential for sensitive data exposure warrant immediate attention.
OpenCVE Enrichment