Description
Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.
Published: 2026-09-01
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Filesystem Access via Missing Authentication
Action: Patch Now
AI Analysis

Impact

The vulnerability in Dell PowerStore SDNAS is a Missing Authentication for a critical function. An unauthenticated attacker with remote access could exploit the flaw, allowing unauthorized filesystem access. This weakness is classified as CWE‑306, indicating that authentication is omitted before performing a sensitive operation.

Affected Systems

Affected products include Dell PowerStore models 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T and 9200T. No specific firmware or software version ranges were supplied in the advisory, so any currently deployed instance of the listed models may be vulnerable.

Risk and Exploitability

With a CVSS score of 9 the vulnerability is high‑severity and can be exploited remotely over the network. The advisory does not provide an EPSS score and the vulnerability is not listed in the CISA KEV catalog, so the publicly reported exploit probability is currently unknown. Based on the description the likely attack vector is remote access to a management or data service, which suggests that an attacker with network connectivity can achieve filesystem access without authentication.

Generated by OpenCVE AI on September 2, 2026 at 02:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerStore T security update (DSA‑2026‑330) to all affected systems.
  • Restrict network reachability to the PowerStore management network only to trusted hosts, using firewall or VLAN segmentation.
  • Ensure that authentication is required for all PowerStore APIs and services; verify that no management endpoints are left open to unauthenticated traffic.

Generated by OpenCVE AI on September 2, 2026 at 02:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t

Wed, 02 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title Missing Authentication in Dell PowerStore Allows Unauthorized Filesystem Access

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-02T03:55:51.285Z

Reserved: 2026-08-25T12:04:33.629Z

Link: CVE-2026-79687

cve-icon Vulnrichment

Updated: 2026-09-01T16:14:07.419Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T16:17:20.160

Modified: 2026-09-02T04:18:02.540

Link: CVE-2026-79687

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T03:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function