ZeroHour

CVE-2026-58574

large

Unauthenticated info disclosure in Dell PowerStore management interface

CVSS 3.1
9.8 critical
EPSS
<1%p27
Published
()
Modified
AI analysis

Dell PowerStore contains a missing-authentication flaw (CWE-306) in its restricted management interface that allows an unauthenticated attacker with network access to read internal system information from the appliance filesystem. The flaw is triggered simply by sending network requests to the exposed management interface, with no credentials or user interaction required. Because the readable filesystem data can include sensitive information and credentials, an attacker could escalate to full administrative access to the array. Any organization running Dell PowerStore whose management interface is reachable over the network is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.3% chance of exploitation within 30 days.

What to do: Check the Dell security advisory for CVE-2026-58574 to identify affected PowerStore versions and upgrade to the patched release Dell provides. Until patched, restrict access to the management interface with network segmentation or firewall rules so unauthenticated users cannot reach it. Because the flaw can expose administrative credentials, prioritize patching arrays on shared or broadly reachable management networks.

Affected
Dell PowerStore
Estimated exposure
large≈ tens of thousands of deployed PowerStore arrays worldwide (exact install base not publicly disclosed) — PowerStore has been a widely sold Dell midrange enterprise storage line since 2020, making a five-figure global install base a reasonable estimate, though the remotely exploitable population is smaller because only deployments whose…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array.

Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.