Junglewise Threat Intelligence

CVE-2025-32749: Dell PowerFlex Manager incorrect default permissions privilege escalation

CVE-2025-32749 · Severity: medium · CVSS 5.3 · Published 2026-05-22

Technologies: Dell PowerFlex Manager, Dell Powerflex Rack, Dell Powerflex Appliance Intelligent Catalog. Vendors: Dell.

Executive brief

Dell PowerFlex Manager is a tool used to manage and automate storage infrastructure. A security flaw in this software allows a user with low-level access to the system to gain higher-level permissions than intended. This could allow an unauthorized individual to modify system settings or access restricted data, potentially compromising the integrity of the storage management environment.

Technical details

Dell PowerFlex Manager (versions 4.6.2 and prior) is vulnerable to an incorrect default permissions flaw (CWE-276). The vulnerability exists within the file system or component permissions of the management software. A local attacker with low-level privileges can exploit these weak permissions to modify files or execute processes with higher authority, leading to an elevation of privileges. The attack requires local access to the system but no user interaction. Dell has released security updates (DSA-2025-434 and DSA-2025-435) to address this issue in PowerFlex Appliance and Rack configurations.

Affected products

  • Dell PowerFlex Manager <=4.6.2
  • Dell PowerFlex Appliance < IC 48.383.00
  • Dell PowerFlex Rack < 3.8.3.0

Timeline

  • 2026-05-22: disclosed
  • 2026-05-22: advisory

References

Related threats