CVE-2026-79683

8.8

Dell · PowerStore

Dell PowerStore systems contain a protection mechanism failure that allows an authenticated user with limited privileges to write attacker-controlled content to arbitrary filesystem paths.

Executive summary

A high-severity protection mechanism failure in Dell PowerStore allows authenticated users to perform arbitrary file writes, potentially leading to full system compromise.

Vulnerability

This vulnerability is a protection mechanism failure, classified as CWE-693, which enables an authenticated user with limited privileges to manipulate filesystem paths and write unauthorized content. The vulnerability is exploitable over the network without requiring user interaction.

Business impact

Successful exploitation allows an attacker to write arbitrary content to the filesystem, which can be leveraged to escalate privileges, overwrite system configuration files, or execute malicious code. Given the CVSS score of 8.8, this vulnerability poses a significant risk to data integrity and system availability, as it effectively bypasses standard security controls on the storage appliance.

Remediation

Immediate Action: Update all affected Dell PowerStore appliances to version 4.1.0.6-2771237 or later as specified in the Dell security advisory DSA-2026-330.

Proactive Monitoring: Review system access logs for unusual file write activity or unauthorized attempts to access sensitive system directories by low-privileged accounts.

Compensating Controls: Restrict administrative and low-level access to the PowerStore management interface to authorized personnel only, and ensure the management network is isolated from non-essential traffic.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The vulnerability represents a significant risk to the integrity of the storage environment. Administrators should prioritize the deployment of the vendor-provided patch immediately to eliminate the potential for unauthorized filesystem modification and privilege escalation.

More Dell CVEs

Sources