Executive brief
Dell PowerFlex Manager, a tool used to manage and automate software-defined storage infrastructure, contains a security flaw that allows unauthorized users to view file directories. An attacker could use this to browse internal system files and access sensitive information remotely. This could lead to the exposure of configuration details or other data that could be used to further compromise the storage environment.
Technical details
Dell PowerFlex Manager (versions <= 4.6.2) is vulnerable to CWE-548: Exposure of Information Through Directory Listing. The vulnerability exists because the web server component fails to properly restrict directory browsing, allowing an unauthenticated attacker with network access to the management interface to view the contents of directories. By exploiting this, an attacker can discover and retrieve sensitive files that are not intended for public access. Dell has released security updates (DSA-2025-434 and DSA-2025-435) to address this and other vulnerabilities in the PowerFlex ecosystem.
Affected products
- Dell PowerFlex Manager <= 4.6.2
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory
References
- https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities
- https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities