Executive brief
Dell PowerFlex Manager is a tool used to manage and automate storage infrastructure. A security flaw in this software allows a user with low-level access to the system to gain higher-level permissions than intended. This could allow an unauthorized individual to modify system settings or access restricted data, potentially compromising the integrity of the storage management environment.
Technical details
Dell PowerFlex Manager (versions 4.6.2 and prior) is vulnerable to an incorrect default permissions flaw (CWE-276). The vulnerability exists within the file system or component permissions of the management software. A local attacker with low-level privileges can exploit these weak permissions to modify files or execute processes with higher authority, leading to an elevation of privileges. The attack requires local access to the system but no user interaction. Dell has released security updates (DSA-2025-434 and DSA-2025-435) to address this issue in PowerFlex Appliance and Rack configurations.
Affected products
- Dell PowerFlex Manager <=4.6.2
- Dell PowerFlex Appliance < IC 48.383.00
- Dell PowerFlex Rack < 3.8.3.0
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory
References
- https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities
- https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities