Executive brief
Dell PowerFlex Manager, a tool used to manage and automate software-defined storage infrastructure, contains a security flaw in how it validates digital certificates. An attacker on the same local network could exploit this to intercept or modify communications between the management software and other systems. This could lead to unauthorized data tampering or the exposure of sensitive management information.
Technical details
Dell PowerFlex Manager (versions 4.6.2 and prior) is vulnerable to improper certificate validation (CWE-295). The root cause is a failure to correctly verify the authenticity of SSL/TLS certificates during communication. An unauthenticated attacker with adjacent network access (on the same local subnet or broadcast domain) can exploit this via a Man-in-the-Middle (MitM) attack. Successful exploitation allows the attacker to intercept, view, or modify data in transit, potentially leading to information tampering or disclosure. Remediation is available through vendor-provided security updates for PowerFlex Appliance and Rack configurations.
Affected products
- Dell PowerFlex Manager <=4.6.2
- Dell PowerFlex Rack < 3.7.8.0, < 3.8.3.0
- Dell PowerFlex Appliance Intelligent Catalog < 48.383.00
Timeline
- 2026-05-22: advisory: Initial disclosure by Dell and NVD publication
References
- https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities
- https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities