AI analysis
Dell Container Storage Modules (CSM) prior to version 1.18.0 ship with hard-coded credentials in the csm-docs component (CWE-798). An unauthenticated attacker with remote access to an affected deployment can exploit the embedded credentials without any user interaction, and the flaw is scored 9.8 critical with high impact on confidentiality, integrity, and availability, although Dell's advisory specifically cites information disclosure as the outcome. The product is affected only in versions before 1.18.0, so any organization running an older CSM release alongside Dell storage arrays in Kubernetes environments is exposed. This CVE was fixed as part of a broader batch of 18 critical Dell CSM vulnerabilities that Dell has urged administrators to patch immediately, some of which grant unauthenticated administrative access. There is no known public proof-of-concept and no evidence of in-the-wild exploitation to date.
What to do: Upgrade Dell Container Storage Modules to version 1.18.0 or later as soon as possible, since Dell patched this alongside 17 other critical CSM flaws. Because the flaw is a hard-coded credential in csm-docs reachable without authentication, review access logs on any exposed CSM components and rotate storage-related secrets, tokens, and credentials that the documentation component could have disclosed. If immediate upgrade is not feasible, restrict network access to CSM services until patched.
Affected
| Dell Container Storage Modules (CSM) | prior to 1.18.0 |
Estimated exposure
nicheunknown; plausibly hundreds to low thousands of enterprise Kubernetes clusters — CSM is an enterprise-only storage integration layer for Dell arrays (deployed per Kubernetes cluster rather than per user), and no public install counts or internet-scan data exist for it.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8