Executive brief
Dell Container Storage Modules, which allow Kubernetes clusters to interact with Dell storage arrays, contain a security flaw that could allow an attacker to take control of the underlying system. A highly privileged attacker with remote access could execute unauthorized commands on the storage infrastructure. This could lead to a total loss of data confidentiality and integrity, as well as service disruptions.
Technical details
An OS command injection vulnerability (CWE-78) exists in multiple Dell Container Storage Modules (CSM) CSI drivers due to improper neutralization of special elements. The vulnerability affects the CSI drivers for PowerFlex, PowerStore, Unity XT, and PowerMax. A remote attacker with high privileges can exploit this flaw to execute arbitrary OS commands on the host system. The attack complexity is rated as high, suggesting specific environmental conditions or configurations may be required for successful exploitation. Dell has released remediated versions (v2.15.2 and v2.17.0 depending on the specific driver) to address this issue.
Affected products
- Dell Container Storage Modules CSI Driver for Dell PowerFlex 2.15.0 through 2.15.1, and versions prior to 2.17.0
- Dell Container Storage Modules CSI Driver for Dell PowerStore Versions prior to 2.17.0
- Dell Container Storage Modules CSI Driver for Dell Unity XT Versions prior to 2.17.0
- Dell Container Storage Modules CSI Driver for Dell PowerMax Versions prior to 2.17.0
Timeline
- 2026-06-26: advisory: Initial advisory published by Dell and NVD.