Executive brief
Dell PowerFlex rack, a hyper-converged infrastructure solution for data centers, is vulnerable to a flaw that allows attackers to redirect users to malicious websites. By manipulating web traffic headers, an unauthenticated remote attacker could trick legitimate users into visiting fraudulent sites, potentially leading to phishing or credential theft. This issue primarily impacts the integrity of user sessions and the reputation of the management interface.
Technical details
A Host Header Injection vulnerability (CWE-601) exists in Dell PowerFlex rack RCM versions 3.7 and 3.8. An unauthenticated remote attacker can exploit this by submitting a specially crafted HTTP Host header. The application fails to properly validate this header, using it to generate links or redirects. This can be leveraged to perform web cache poisoning or to redirect users to untrusted external domains (Open Redirect). User interaction is required to click a manipulated link. Remediation is available in versions 3.8.4.1, 3.9.1.1, and later.
Affected products
- Dell PowerFlex rack RCM 3.7, 3.8.x prior to 3.8.4.1, 3.9.x prior to 3.9.1.1
Timeline
- 2026-06-17: advisory: Initial disclosure by Dell and NVD publication