CVE-2026-79687
largeMissing Authentication in Dell PowerStore SDNAS Allows Unauthenticated Filesystem Access
Dell PowerStore SDNAS, the NAS/file-services component of Dell PowerStore storage arrays, has a missing-authentication flaw (CWE-306): a critical function can be reached without any credentials. An unauthenticated attacker with remote network access to the SDNAS interface can trigger the flaw, though the CVSS score reflects high attack complexity, so some non-trivial conditions are involved. A successful attacker gains filesystem access, with high impact on confidentiality, integrity, and availability, and the changed scope in the CVSS vector indicates the impact extends beyond the SDNAS component itself to the broader system. Only organizations running Dell PowerStore arrays with the SDNAS (NAS file services) component enabled and network-reachable are affected. There is currently no public proof-of-concept, no CISA KEV listing, and no known exploitation, with EPSS estimating only about a 0.3% probability of exploitation within 30 days.
What to do: Upgrade PowerStore systems to the fixed software release identified in Dell's security advisory, as the available data does not specify affected or fixed version ranges. Until patching is complete, restrict SDNAS/NAS interfaces to trusted network segments and verify whether SDNAS file services are enabled and reachable by unauthenticated users. Monitor the Dell advisory for updated affected-version and remediation details.
| Dell PowerStore SDNAS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.