Executive brief
Dell PowerFlex Manager, a tool used to manage and automate software-defined storage infrastructure, contains a security flaw in how it verifies user identity. An attacker located on the same local network could bypass security checks to gain unauthorized access to the system. This could allow an attacker to modify system configurations or disrupt storage operations, potentially impacting data availability and integrity.
Technical details
An improper authentication vulnerability (CWE-287) exists in Dell PowerFlex Manager. The flaw allows an unauthenticated attacker with adjacent network access (on the same local subnet or broadcast domain) to bypass authentication mechanisms. Successful exploitation leads to unauthorized access with the ability to perform high-integrity modifications or cause service disruptions. The vulnerability is addressed in PowerFlex versions 4.5.5.2 and 5.1.0.1 or later.
Affected products
- Dell PowerFlex Manager Versions prior to 4.5.5.2, versions prior to 5.1.0.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory