AI analysis
Dell Container Storage Modules (CSM), versions prior to 1.18.0, fail to require authentication for a critical function, classified as CWE-306 (Missing Authentication for Critical Function). An unauthenticated attacker with remote access to the affected service can trigger this function directly, with no user interaction, and gain elevated privileges. The CVSS 3.1 score is a maximum 10.0 with scope changed and high impact on confidentiality, integrity, and availability, and related reporting indicates the flaw set could allow unauthenticated attackers to gain full administrative control over storage and Kubernetes resources, including root-level access on Kubernetes nodes. Any organization running Dell CSM for Kubernetes storage integration with Dell arrays on a version older than 1.18.0 is affected. There is no known public proof of concept and no confirmed in-the-wild exploitation to date, though Dell is urging administrators to patch immediately.
What to do: Upgrade Dell Container Storage Modules to version 1.18.0 or later as soon as possible, since this is one of 18 critical flaws Dell patched in CSM. Until patched, restrict network access to all CSM services, APIs, and metrics endpoints so only trusted cluster nodes and administrators can reach them. Review Kubernetes audit logs and CSM service logs for unauthenticated or anomalous requests, and check whether service account RBAC permissions have been unexpectedly modified.
Affected
| Dell (Dell EMC) Container Storage Modules (CSM) | versions prior to 1.18.0 |
Estimated exposure
moderatelikely on the order of a few thousand enterprise Kubernetes/storage deployments (10^3–10^4 systems) — Dell CSM is deployed only alongside Dell storage arrays in enterprise Kubernetes environments, has no public install counts, and is typically internal-facing rather than internet-exposed, so precise exposure is uncertain but bounded to…
Description
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.