ZeroHour

CVE-2026-79687

large

Missing Authentication in Dell PowerStore SDNAS Allows Unauthenticated Filesystem Access

CVSS 3.1
9.0 critical
EPSS
<1%p20
Published
()
Modified
AI analysis

Dell PowerStore SDNAS, the NAS/file-services component of Dell PowerStore storage arrays, has a missing-authentication flaw (CWE-306): a critical function can be reached without any credentials. An unauthenticated attacker with remote network access to the SDNAS interface can trigger the flaw, though the CVSS score reflects high attack complexity, so some non-trivial conditions are involved. A successful attacker gains filesystem access, with high impact on confidentiality, integrity, and availability, and the changed scope in the CVSS vector indicates the impact extends beyond the SDNAS component itself to the broader system. Only organizations running Dell PowerStore arrays with the SDNAS (NAS file services) component enabled and network-reachable are affected. There is currently no public proof-of-concept, no CISA KEV listing, and no known exploitation, with EPSS estimating only about a 0.3% probability of exploitation within 30 days.

What to do: Upgrade PowerStore systems to the fixed software release identified in Dell's security advisory, as the available data does not specify affected or fixed version ranges. Until patching is complete, restrict SDNAS/NAS interfaces to trusted network segments and verify whether SDNAS file services are enabled and reachable by unauthenticated users. Monitor the Dell advisory for updated affected-version and remediation details.

Affected
Dell PowerStore SDNAS
Estimated exposure
largetens of thousands of PowerStore arrays deployed, of which only the SDNAS-enabled, network-exposed subset is affected — Dell's PowerStore line has a publicly reported installed base in the tens of thousands of enterprise storage systems, but only deployments where the SDNAS file-services component is enabled and reachable from an untrusted network are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.

Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.