Executive brief
Dell ECS and ObjectScale are enterprise storage systems used to store and manage large volumes of data. These versions contain a weak cryptographic algorithm that could allow a local attacker with high privileges to expose sensitive information stored on the system, compromising data confidentiality.
Technical details
The vulnerability is a use of a broken or risky cryptographic algorithm in Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.4.0.0. The attack requires local access and high privilege level on the affected system. Successful exploitation could lead to information disclosure. The fix is available by upgrading to ObjectScale version 4.4.0.0 or later, or ECS version 4.4.0.0 or later.
Affected products
- Dell Elastic Cloud Storage 3.8.1.0 through 3.8.1.7
- Dell ObjectScale prior to 4.4.0.0
Timeline
- 2026-09-16: disclosed