Executive brief
Dell Unisphere for PowerMax, a management interface for enterprise storage arrays, contains a security vulnerability that could allow an attacker to take full control of the system. By sending specially crafted data, a user with low-level access can bypass security controls to execute commands with the highest level of administrative privileges (root). This could lead to the theft of sensitive data, disruption of storage operations, or complete system compromise.
Technical details
A deserialization of untrusted data vulnerability (CWE-502) exists in Dell Unisphere for PowerMax and its associated virtual appliance. The flaw is located in how the application processes serialized objects provided by users. A remote attacker with low-level authenticated access can exploit this by submitting a malicious serialized object, which, when processed by the server, leads to arbitrary code execution. Successful exploitation grants the attacker root-level privileges on the underlying operating system. Dell has released updates (10.3.0.7 or later, and 10.3.1.1 Patch 11360 or later) to address this issue.
Affected products
- Dell Unisphere for PowerMax 10.3.0.5 and prior
- Dell Unisphere for PowerMax Virtual Appliance 10.3.0.5 and prior
Timeline
- 2026-07-10: advisory: Initial publication of DSA-2026-272 and CVE-2026-54469