Executive brief
Dell Unisphere for PowerMax, a management interface for high-end enterprise storage arrays, contains a security flaw that allows unauthorized file access. An attacker with low-level login credentials can exploit this to read sensitive system files remotely. This could lead to the exposure of configuration data or other confidential information stored on the management appliance.
Technical details
A path traversal vulnerability (CWE-22) exists in Dell Unisphere for PowerMax, Unisphere for PowerMax Virtual Appliance, and Unisphere 360. The flaw is rooted in improper limitation of a pathname to a restricted directory within the web management interface. A remote attacker authenticated with low-level privileges can provide specially crafted input containing directory traversal sequences (e.g., ../) to access files outside of the intended application directory. Successful exploitation allows the attacker to read arbitrary files from the underlying operating system. Dell has released patches in versions 10.3.0.7 and 10.3.1.1 Patch 11360 to address this issue.
Affected products
- Dell Unisphere for PowerMax 10.3.0.5 and prior
- Dell Unisphere for PowerMax Virtual Appliance 10.3.0.5 and prior
- Dell Unisphere 360 10.3.0.5 and prior
Timeline
- 2026-07-10: advisory: Initial publication of Dell security advisory DSA-2026-272
- 2026-07-10: disclosed