Executive brief
Dell PowerFlex Manager is a tool used to manage and automate software-defined storage infrastructure. A security vulnerability in this tool allows a high-privileged user to execute unauthorized commands with the highest level of system permissions (root). If exploited, this could lead to a complete takeover of the management appliance and allow the attacker to move laterally into the connected storage infrastructure.
Technical details
An OS command injection vulnerability (CWE-78) exists in Dell PowerFlex Manager due to improper neutralization of special elements during OS Repository processing. A remote attacker with high privileges can exploit this flaw to execute arbitrary commands as root on the underlying operating system. The vulnerability is characterized by a CVSS 3.1 score of 9.1, reflecting its high impact and the potential for scope change (S:C), which could lead to lateral movement within the managed infrastructure. Dell has released patches in versions 5.1.0.1 and 4.5.5.2 to address this issue.
Affected products
- Dell PowerFlex Manager Prior to 5.1.0.1, prior to 4.5.5.2
Timeline
- 2026-07-10: advisory: Dell published the security update DSA-2026-066.
- 2026-07-10: disclosed