ZeroHour

CVE-2026-58572

large

Authenticated Code Injection in Dell PowerStore Grants Root Privileges

CVSS 3.1
8.8 high
EPSS
<1%p8
Published
()
Modified
AI analysis

Dell PowerStore, Dell's enterprise storage array, contains a code injection flaw (CWE-94) in its software. The flaw is triggered when an authenticated user with limited privileges — someone holding valid low-privilege credentials on the appliance — submits crafted input that gets executed as code, consistent with the CVSS local attack vector (AV:L) indicating exploitation via local/management access rather than anonymous remote access. A successful attacker executes arbitrary code with root privileges on the appliance (CVSS scope change from user context to root, with high impact on confidentiality, integrity, and availability), giving full control over the storage system and the data it serves. Organizations running Dell PowerStore arrays are affected; the available data does not specify which PowerStore versions are impacted, so defenders should consult Dell's official security advisory for the affected range. Exploitation has not been observed: EPSS is just 0.2% (8th percentile), the flaw is not in CISA's KEV catalog, and no public proof-of-concept is known.

What to do: Apply the PowerStore operating system update referenced in Dell's security advisory for this CVE — the available data does not list fixed versions, so pull the exact remediated release from the Dell advisory before patching. Until patched, audit and restrict low-privilege local accounts that can reach the array's management interface (UI/CLI/API), and keep management access confined to trusted management networks rather than routable or internet-exposed segments. Monitor the Dell advisory for updated affected-version details and any emerging exploitation guidance.

Affected
Dell PowerStore
Estimated exposure
large≈10,000–100,000 deployed PowerStore systems worldwide (enterprise arrays in private data centers, rarely internet-exposed) — PowerStore has been Dell's mainstream midrange array since 2020 and is widely deployed in enterprise data centers; these appliances sit behind management networks rather than being internet-exposed, so the estimate is an order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.

Weakness
CWE-94
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.