Executive brief
Dell PowerScale InsightIQ is a performance monitoring and reporting tool for scale-out storage systems. A vulnerability in this software allows an attacker who already has high-level access to the local system to execute tasks with even higher privileges. This could lead to a complete takeover of the monitoring appliance and potential disruption of storage analytics.
Technical details
Dell PowerScale InsightIQ (versions 5.0.0 to 6.2.0) is vulnerable to an 'Execution with Unnecessary Privileges' (CWE-250) flaw. The vulnerability exists because certain components or processes run with higher privileges than required for their intended function. An attacker who has already obtained high-privileged local access to the InsightIQ system can exploit this misconfiguration to further elevate their privileges, potentially reaching root or administrative control over the underlying operating system. The issue is resolved in version 6.3.0 or later.
Affected products
- Dell PowerScale InsightIQ 5.0.0 through 6.2.0
Timeline
- 2026-05-11: advisory: Initial release of Dell Security Advisory DSA-2026-208
- 2026-05-12: disclosed: NVD publication date