Executive brief
Dell PowerFlex Manager is a tool used to manage and automate storage infrastructure. A security flaw in versions 4.6.2 and earlier allows a user with low-level access to the system to view sensitive information that is not properly protected. This could lead to the exposure of credentials or configuration data, potentially allowing an attacker to gain further unauthorized access to the storage environment.
Technical details
Dell PowerFlex Manager (including Appliance and Rack variants) is vulnerable to insecure storage of sensitive information (CWE-922). The vulnerability exists in versions up to and including 4.6.2. A low-privileged attacker with local access to the management system can exploit this flaw to read sensitive data that has been stored without adequate protection. The attack vector is local and requires no user interaction. Successful exploitation results in a high impact on confidentiality but does not directly affect integrity or availability. Remediation is available through vendor-provided security updates (DSA-2025-434 and DSA-2025-435).
Affected products
- Dell PowerFlex Manager <= 4.6.2
- Dell PowerFlex Rack < 3.7.8.0, < 3.8.3.0
- Dell PowerFlex Appliance Intelligent Catalog < 48.383.00
Timeline
- 2026-05-22: advisory: Initial disclosure by Dell
- 2026-05-22: disclosed
References
- https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities
- https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities