Executive brief
Dell PowerFlex Manager, a tool used to manage and automate software-defined storage infrastructure, contains a security flaw in its access control mechanisms. A user with low-level access to the local network could exploit this to gain higher-level permissions or access sensitive data they are not authorized to see. This could lead to unauthorized configuration changes or exposure of internal system information.
Technical details
An improper access control vulnerability (CWE-284) exists in Dell PowerFlex Manager. The flaw allows a low-privileged attacker with adjacent network access to bypass intended restrictions, leading to elevation of privileges and unauthorized access to sensitive information. The vulnerability is triggered without user interaction. Dell has released security updates in versions 4.5.5.2 and 5.1.0.1 to address this issue. The CVSS score of 5.7 reflects high confidentiality impact but no impact on integrity or availability from this specific flaw.
Affected products
- Dell PowerFlex Manager Versions prior to 4.5.5.2, versions prior to 5.1.0.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory