Executive brief
Dell PowerFlex Manager, a tool used for managing software-defined storage infrastructure, is vulnerable to a security flaw that could allow an authorized user on the local network to access restricted information. While the risk is relatively low, it could allow a user with limited permissions to view data they are not supposed to see. Organizations should update to the latest versions to ensure their storage management environment remains secure.
Technical details
An SQL injection vulnerability (CWE-89) exists in Dell PowerFlex Manager due to improper neutralization of special elements used in SQL commands. An attacker with low-level privileges and adjacent network access (local network) can exploit this flaw to execute unauthorized queries against the underlying database. Successful exploitation leads to unauthorized information disclosure. The vulnerability is addressed in PowerFlex versions 4.5.5.2 and 5.1.0.1 or later.
Affected products
- Dell PowerFlex Manager Versions prior to 4.5.5.2, versions prior to 5.1.0.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory