Executive brief
Dell PowerFlex Manager, a tool used to manage and automate software-defined storage infrastructure, is vulnerable to a security flaw that could allow an unauthorized user to access sensitive information. By tricking a user into interacting with a malicious link or resource, an attacker could gain access to data they are not authorized to see, potentially compromising the management of the storage environment.
Technical details
Dell PowerFlex Manager versions prior to 4.8 contain a CWE-829 (Inclusion of Functionality from Untrusted Control Sphere) vulnerability. This flaw allows an unauthenticated remote attacker to potentially execute malicious functionality or access sensitive data by influencing the application to include resources from an untrusted source. Exploitation requires a high level of complexity and user interaction (UI:R), such as a legitimate user clicking a crafted link. If successful, the attacker can achieve significant information disclosure. Dell has released version 4.8 and subsequent patches (such as 4.5.5.2 and 5.1.0.1) to remediate this issue.
Affected products
- Dell PowerFlex Manager Prior to 4.8
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory