Impact
The vulnerability in Dell PowerStore SDNAS is a Missing Authentication for a critical function. An unauthenticated attacker with remote access could exploit the flaw, allowing unauthorized filesystem access. This weakness is classified as CWE‑306, indicating that authentication is omitted before performing a sensitive operation.
Affected Systems
Affected products include Dell PowerStore models 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T and 9200T. No specific firmware or software version ranges were supplied in the advisory, so any currently deployed instance of the listed models may be vulnerable.
Risk and Exploitability
With a CVSS score of 9 the vulnerability is high‑severity and can be exploited remotely over the network. The advisory does not provide an EPSS score and the vulnerability is not listed in the CISA KEV catalog, so the publicly reported exploit probability is currently unknown. Based on the description the likely attack vector is remote access to a management or data service, which suggests that an attacker with network connectivity can achieve filesystem access without authentication.
OpenCVE Enrichment