Hard-Coded Credentials in Dell Container Storage Modules (CSM) Authorization, pre-1.18.0
AI analysis
Dell Container Storage Modules (CSM) versions prior to 1.18.0 contain a use of hard-coded credentials flaw (CWE-798) in the CSM Authorization component. An unauthenticated attacker with network access to the CSM Authorization service can use the embedded credentials to impersonate a trusted identity and bypass authentication. Successful exploitation gives the attacker elevated privileges — press coverage of this flaw cluster indicates full administrative control over storage management and, in the worst case, root-level access on Kubernetes worker nodes. The affected population is organizations running Dell CSM (the CSI-driver and data-protection tooling for Dell arrays such as PowerStore, PowerFlex, PowerMax and PowerScale on Kubernetes) with versions older than 1.18.0, and specifically those that have deployed the CSM Authorization module. There is no known public proof-of-concept, the CVE is not on CISA's KEV list, and no exploitation in the wild has been reported to date.
What to do: Upgrade Dell CSM, including the CSM Authorization module, to version 1.18.0 or later as soon as possible — Dell has urged admins to patch immediately. First confirm whether CSM Authorization is deployed at all (it is optional; clusters not using it are not exposed to this specific flaw), and restrict network access to the authorization service to trusted internal networks. After patching, rotate any tokens or credentials issued through CSM Authorization and review audit logs for unexpected administrative or tenant-level activity.
Affected
| Dell Container Storage Modules (CSM) — CSM Authorization component | all versions prior to 1.18.0 (< 1.18.0) |
Estimated exposure
moderatelikely on the order of 1,000–10,000 installations (a few thousand Kubernetes deployments), estimate only — CSM Authorization is an optional enterprise component of Dell's Kubernetes storage stack for Dell arrays, so the base is enterprise clusters rather than a mass-market product; no public install counts or internet-scan figures were…
Description
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.