Executive brief
Dell PowerFlex Manager, a tool used to manage and automate software-defined storage environments, contains a security flaw in how it verifies user identity. An attacker on the same local network could bypass security checks to gain unauthorized access to the system. This could allow them to view or modify sensitive configuration data, potentially compromising the integrity of the storage infrastructure.
Technical details
An improper authentication vulnerability (CWE-287) exists in Dell PowerFlex Manager. The flaw allows an unauthenticated attacker with adjacent network access (local subnet) to bypass identity verification mechanisms. Successful exploitation can lead to unauthorized access, information disclosure, and information tampering. The vulnerability is addressed in PowerFlex versions 4.5.5.2 and 5.1.0.1 or later. The CVSS score of 7.4 reflects a high impact on confidentiality with a 'Changed' scope, indicating the potential to impact components beyond the immediate security scope of the manager.
Affected products
- Dell PowerFlex Manager Versions prior to 4.5.5.2; Versions prior to 5.1.0.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory