Executive brief
Dell PowerScale InsightIQ, a performance monitoring and reporting tool for storage systems, is vulnerable to a security flaw that allows high-privileged users to execute unauthorized operating system commands. An attacker with existing administrative access to the local system could exploit this to gain full control over the underlying server environment. This could lead to significant service disruptions or unauthorized access to sensitive storage management data.
Technical details
An OS command injection vulnerability (CWE-78) exists in Dell PowerScale InsightIQ versions 6.0.0 through 6.2.0 due to improper neutralization of special elements used in OS commands. The vulnerability requires local access and high privileges (PR:H) to exploit. Successful exploitation allows the attacker to execute arbitrary commands with the privileges of the application, potentially leading to a full compromise of the host operating system (Scope: Changed). Dell has released version 6.3.0 to remediate this issue.
Affected products
- Dell PowerScale InsightIQ 6.0.0 through 6.2.0
Timeline
- 2026-05-11: advisory: Initial release of Dell Security Advisory DSA-2026-208
- 2026-05-12: disclosed: NVD publication date