Executive brief
Dell Virtual Storage Integrator for VMware vSphere Client is a management tool used to integrate storage systems with VMware environments. An unauthenticated remote attacker can exploit an OS command injection flaw in the IAPI component to execute arbitrary commands as root, achieving complete system compromise and potentially gaining control over the entire storage infrastructure.
Technical details
The vulnerability is an OS command injection flaw in the IAPI component of Dell Virtual Storage Integrator for VMware vSphere Client versions prior to 10.11.1.0. The vulnerability can be exploited remotely without authentication, allowing an attacker to execute arbitrary OS commands with root-level privileges. Attack vector is network-based with no authentication or user interaction required (CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U). Successful exploitation enables complete system takeover, potentially compromising the entire VSI deployment and underlying storage infrastructure. Dell has released patches in version 10.11.1.0 and recommends immediate upgrade.
Affected products
- Dell Virtual Storage Integrator for VMware vSphere Client prior to 10.11.1.0
Timeline
- 2026-08-06: disclosed