Executive brief
Dell PowerFlex Manager is a management tool used to automate and orchestrate software-defined storage environments. A security flaw in this software allows a user with low-level access to disrupt the system's availability. This could lead to a denial-of-service condition, preventing administrators from managing their storage infrastructure.
Technical details
Dell PowerFlex Manager is vulnerable to improper access control (CWE-284). A remote attacker with low-level privileges can exploit this flaw to trigger a denial-of-service (DoS) condition. The vulnerability exists in versions prior to 4.5.5.2 and 5.1.0.1. Exploitation does not require user interaction or high-level administrative rights, though it does require network access and valid low-privileged credentials. Dell has released security updates to address this issue in PowerFlex versions 4.5.5.2 and 5.1.0.1 or later.
Affected products
- Dell PowerFlex Manager Versions prior to 4.5.5.2, versions prior to 5.1.0.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory