Description
Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information.
Published: 2026-09-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

Dell PowerStore storage arrays contain an Argument Injection flaw that allows an authenticated user with limited privileges to inject arbitrary command-line arguments. This flaw enables the attacker to bypass normal authorization controls and retrieve sensitive system data normally restricted to privileged users. The resulting impact is the disclosure of confidential system information, potentially exposing configuration, management, and stored data.

Affected Systems

Affected systems include Dell PowerStore models such as 1000T, 1200T, 3000T, 3200Q, 3200T, 500T, 5200Q, 5200T, 5000T, 7000T, 9000T, and 9200T. All listed variants are subject to the Argument Injection vulnerability and should be evaluated for the presence of the issued security update.

Risk and Exploitability

The CVSS score of 6.5 places this flaw in the moderate seriousness bracket, and the lack of an EPSS value indicates that current exploitation probability data is unavailable. Since the vulnerability requires prior authenticated access with limited privileges, it is most likely to be leveraged by insiders or compromised accounts rather than by remote unauthenticated attackers. The flaw is not present in the CISA KEV catalog, suggesting no known widespread exploitation, but its moderate severity and potential for sensitive data exposure warrant immediate attention.

Generated by OpenCVE AI on September 1, 2026 at 15:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Dell PowerStore update referenced in Dell DSA 2026‑330 to eliminate the Argument Injection flaw.
  • Restrict authenticated users to the minimum privileges necessary for their roles and remove any accounts with excessive rights that could exploit the vulnerability.
  • Configure monitoring or alerting to detect unusual command-line argument usage or repeated attempts to access privileged system data.

Generated by OpenCVE AI on September 1, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Argument Injection Enables Unauthorized Access to Sensitive System Information
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information.
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-01T15:29:04.640Z

Reserved: 2026-08-25T12:04:33.629Z

Link: CVE-2026-79685

cve-icon Vulnrichment

Updated: 2026-09-01T15:29:00.531Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T15:17:29.390

Modified: 2026-09-01T21:12:11.590

Link: CVE-2026-79685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T16:00:13Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')