Executive brief
Dell SmartFabric Storage Software is used to manage and automate storage connectivity in data center networks. A vulnerability in this software could allow a user with high-level administrative access to bypass security controls and gain unauthorized access to the underlying file system. This could lead to the theft of sensitive data or the disruption of storage operations.
Technical details
A command injection vulnerability (CWE-77) exists in Dell SmartFabric Storage Software versions prior to 1.4.5 due to improper neutralization of special elements used in a command. The vulnerability requires the attacker to have high privileges (PR:H) and local access (AV:L) to the system. Additionally, the attack complexity is considered high (AC:H), suggesting specific conditions or timing are required for successful exploitation. If exploited, an attacker can achieve unauthorized filesystem access, potentially compromising the confidentiality, integrity, and availability of the system. Dell has released version 1.4.5 to address this issue.
Affected products
- Dell SmartFabric Storage Software prior to 1.4.5
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory