ZeroHour

CVE-2026-58569

large

Local privilege escalation to root in Dell PowerStore (untrusted functionality inclusion)

CVSS 3.1
8.8 high
EPSS
<1%p3
Published
()
Modified
AI analysis

Dell PowerStore arrays contain a CWE-829 'Inclusion of Functionality from Untrusted Control Sphere' flaw, meaning the appliance loads or incorporates functionality (such as code or libraries) from a source outside its trusted control boundary. An authenticated user with only limited privileges who has local access to the system can trigger the flaw, and no user interaction is required. Successful exploitation lets the attacker execute arbitrary code with root privileges on the array, effectively a full compromise of the appliance (CVSS scope change with high confidentiality, integrity, and availability impact). Any organization running an affected Dell PowerStore system is exposed, particularly where low-privileged users can authenticate to local or management interfaces on the appliance. Exploitation status is quiet so far: no public proof of concept, not listed in CISA's KEV catalog, and EPSS estimates only about a 0.1% probability of exploitation within 30 days.

What to do: Upgrade PowerStore systems to the fixed release identified in Dell's security advisory (the available data does not specify affected or fixed version numbers). Until patched, restrict which accounts can authenticate locally to PowerStore (for example SSH and management interfaces) and remove unnecessary low-privileged access, since exploitation requires an authenticated local session. Check Dell's advisory for exact affected version ranges and schedule the update at the next maintenance window.

Affected
Dell PowerStore
Estimated exposure
largeon the order of tens of thousands of deployed PowerStore systems worldwide (exact installed base not disclosed) — PowerStore is Dell's flagship midrange enterprise storage array with a multi-year installed base; public shipment reporting and typical enterprise deployment patterns suggest tens of thousands of systems, though as a local-vector flaw only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges..

Weakness
CWE-829
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.