Unauthenticated Credential Theft in Dell Container Storage Modules (CSM) gRPC Server
AI analysis
Dell Container Storage Modules (CSM) before v1.18.0 ships a csm-authorization-storage gRPC server that fails to authenticate callers on a critical function (CWE-306). An unauthenticated remote attacker who can reach the gRPC endpoint can invoke that function and retrieve the storage backend administrator credentials for every storage array registered with the CSM Authorization module. Because those credentials typically grant full administrative control of the underlying storage systems, the flaw can cascade into complete compromise of storage and, by extension, the Kubernetes workloads depending on it. The bug scores a perfect CVSS 3.1 of 10.0 (network, low complexity, no privileges or user interaction, scope change, high impact to confidentiality, integrity, and availability). Dell has patched the issue and is urging admins to apply updates promptly, but there is no known public PoC and no confirmed in-the-wild exploitation, and it is not yet on the CISA KEV list.
What to do: Upgrade Dell CSM to v1.18.0 or later immediately, prioritizing any cluster running the CSM Authorization module. Until patched, restrict network access to the csm-authorization-storage gRPC server (e.g., Kubernetes NetworkPolicies and firewall rules limiting reachability to trusted pods/segments only) and verify it is not exposed outside the cluster. After patching, rotate the administrator credentials for all registered storage arrays and audit logs for unexplained gRPC calls or suspicious storage-array logins, since the credentials could have been silently harvested before the fix.
Affected
| Dell Container Storage Modules (CSM) - csm-authorization-storage gRPC server (CSM Authorization module) | prior to v1.18.0 (< 1.18.0) |
Estimated exposure
moderatelikely low thousands of installations (thousands of Kubernetes clusters running CSM Authorization against Dell storage arrays) — CSM Authorization is an opt-in enterprise module for Dell storage customers using Kubernetes, typically one instance per cluster and not designed for internet exposure, so the affected population is a subset of Dell's enterprise storage…
Description
Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays.