Executive brief
Dell VxRail, a hyper-converged infrastructure platform used to manage virtualized IT environments, contains a vulnerability where user passwords are stored in plain text. An authorized system administrator could discover these credentials, potentially allowing them to take over other user accounts or escalate their access within the management interface. This could lead to unauthorized configuration changes or access to sensitive administrative functions.
Technical details
Dell VxRail Manager versions prior to 7.0.200 are vulnerable to plain-text password storage, specifically categorized as CWE-532 (Insertion of Sensitive Information into Log File). The vulnerability requires local access and high privileges (sys-admin) to exploit. An attacker with these privileges can access stored credentials in plain text, which can then be used to authenticate as other users within the VxRail Manager application. This results in a loss of confidentiality, integrity, and availability for the affected accounts. Users are advised to upgrade to version 7.0.200 or later to remediate the issue.
Affected products
- Dell VxRail versions before 7.0.200
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory