Executive brief
Dell PowerFlex Manager, a tool used to manage and automate software-defined storage infrastructure, is vulnerable to a security flaw in how it validates digital certificates. An attacker could exploit this to intercept or modify communications between the management software and other systems. This could lead to the exposure of sensitive information or unauthorized changes to the storage environment, especially if combined with other network-based attacks.
Technical details
Dell PowerFlex Manager contains an improper certificate validation vulnerability (CWE-295). The software fails to correctly verify the identity of remote entities during TLS/SSL handshakes. A remote, unauthenticated attacker can exploit this flaw to perform a man-in-the-middle (MitM) attack, particularly when used in conjunction with DNS cache poisoning. Successful exploitation allows the attacker to intercept, decrypt, or modify traffic between the PowerFlex Manager and its connected endpoints. The vulnerability is addressed in versions 4.5.1.1, 4.5.5.2, 5.1.0.1, and later.
Affected products
- Dell PowerFlex Manager prior to 4.5.1.1, 4.5.5.2, or 5.1.0.1
Timeline
- 2026-06-17: advisory: Initial disclosure by Dell and NVD publication