Executive brief
Dell PowerStore is an enterprise storage system used to manage and store critical business data. A low-privileged local attacker could exploit a path traversal vulnerability to modify arbitrary system files, potentially compromising system integrity, availability, or leading to unauthorized access to stored data.
Technical details
A path traversal vulnerability exists in the Dell PowerStore Service user functionality that allows local attackers with low privileges to bypass directory restrictions and access or modify arbitrary system files. The vulnerability is accessible without user interaction and requires only local access to an affected system. An attacker can exploit this to corrupt critical system files or modify security controls. Patches are available in PowerStoreT OS version 4.3.1.1-2726662 and later.
Affected products
- Dell PowerStore 500T PowerStoreT OS 4.3.0.0-2611831 through 4.3.1.0-2662695
- Dell PowerStore 1000T PowerStoreT OS 4.3.0.0-2611831 through 4.3.1.0-2662695
- Dell PowerStore 1200T PowerStoreT OS 4.3.0.0-2611831 through 4.3.1.0-2662695
- Dell PowerStore 3000T PowerStoreT OS 4.3.0.0-2611831 through 4.3.1.0-2662695
- Dell PowerStore 3200Q PowerStoreT OS 4.3.0.0-2611831 through 4.3.1.0-2662695
- Dell PowerStore 3200T PowerStoreT OS 4.3.0.0-2611831 through 4.3.1.0-2662695
- Dell PowerStore 5000T PowerStoreT OS 4.3.0.0-2611831 through 4.3.1.0-2662695
- Dell PowerStore 5200Q PowerStoreT OS 4.3.0.0-2611831 through 4.3.1.0-2662695
- Dell PowerStore 5200T PowerStoreT OS 4.3.0.0-2611831 through 4.3.1.0-2662695
- Dell PowerStore 7000T PowerStoreT OS 4.3.0.0-2611831 through 4.3.1.0-2662695
- Dell PowerStore 9000T PowerStoreT OS 4.3.0.0-2611831 through 4.3.1.0-2662695
- Dell PowerStore 9200T PowerStoreT OS 4.3.0.0-2611831 through 4.3.1.0-2662695
Timeline
- 2026-04-01: disclosed
- 2026-04-01: patched: PowerStoreT OS version 4.3.1.1-2726662 or later