ZeroHour

CVE-2026-58567

large

OS Command Injection in Dell PowerStore Enables Root-Level Command Execution

CVSS 3.1
8.8 high
EPSS
<1%p42
Published
()
Modified
AI analysis

Dell PowerStore storage appliances contain an OS command injection vulnerability (CWE-78) in which insufficiently sanitized input is passed to the underlying operating system. The flaw is triggered by an authenticated user with limited privileges, who submits crafted input through the appliance's management functionality, causing arbitrary OS commands to be executed. Because the injected commands run with root privileges, an attacker gains complete control over the appliance, including the ability to read or modify stored data, alter system configuration, or establish persistence. Any organization running affected Dell PowerStore systems where low-privileged accounts exist (for example, restricted support or monitoring users) is exposed. As of now there is no evidence of exploitation in the wild: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.5% chance of exploitation within 30 days.

What to do: Review Dell's security advisory (issued by Dell EMC's PSIRT, CNA [email protected]) for the affected and fixed PowerStore releases and apply the patched operating-system/firmware update as soon as a maintenance window allows. In the interim, restrict or audit low-privileged (non-administrator) CLI and management accounts on PowerStore arrays, since those are the required entry point, and limit management-interface access to trusted administrative networks. Because the vector is local (AV:L) and no public exploit exists, prioritize patching arrays that host sensitive data or expose management access to many users.

Affected
Dell PowerStore
Estimated exposure
largetens of thousands of deployed PowerStore arrays worldwide (Dell has publicly cited a PowerStore customer base in the tens of thousands since the product… — Dell's public statements and analyst reporting indicate PowerStore has been adopted by tens of thousands of enterprise customers, though only arrays with authenticated low-privileged users are practically exploitable and the count is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

Weakness
CWE-78
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.