Executive brief
Dell PowerFlex Manager, a tool used to manage and automate software-defined storage environments, contains a security weakness in its encryption methods. An unauthenticated attacker with network access could exploit this to view or modify sensitive information. This could lead to unauthorized data access or tampering with management configurations.
Technical details
Dell PowerFlex Manager (specifically version 4.6.0.1 and other versions prior to 4.5.5.2 and 5.1.0.1) is vulnerable to CWE-327: Use of a Broken or Risky Cryptographic Algorithm. The flaw allows an unauthenticated remote attacker to exploit weak encryption to perform information disclosure and information tampering. The attack complexity is rated as high, suggesting that successful exploitation may depend on specific environmental conditions or intercepting traffic. Remediation is available in versions 4.5.5.2, 5.1.0.1, and later.
Affected products
- Dell PowerFlex Manager 4.6.0.1, 4.5.x prior to 4.5.5.2, 5.0.x prior to 5.1.0.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory