Executive brief
Dell PowerFlex Manager is a tool used to manage and automate storage infrastructure. A security flaw in certain versions allows an attacker with physical or local access to the system to view sensitive information that has been stored insecurely. This could lead to the exposure of configuration details or other protected data, though it requires the attacker to already have a foothold on the local machine.
Technical details
Dell PowerFlex Manager (including Appliance and Rack configurations) is vulnerable to CWE-922: Insecure Storage of Sensitive Information. The vulnerability exists in versions up to and including 4.6.2. An unauthenticated attacker with local access to the system can exploit this flaw to retrieve sensitive information stored by the application. The attack vector is local, meaning the attacker must have a way to execute commands or access the file system on the host where PowerFlex Manager is running. Dell has released security updates (DSA-2025-434 and DSA-2025-435) to address this and other third-party component vulnerabilities.
Affected products
- Dell PowerFlex Manager <= 4.6.2
- Dell PowerFlex Rack < 3.7.8.0, < 3.8.3.0
- Dell PowerFlex Appliance Intelligent Catalog < 48.383.00
Timeline
- 2026-05-22: disclosed: Initial publication of the advisory
- 2026-05-22: advisory: Dell published DSA-2025-434 and DSA-2025-435
References
- https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities
- https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities