Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HDell Powerflex Manager
APPDell< 4.8.0
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Auth Bypass
CWE
Powiązane podatności
CVE-2026-56688CRITICAL9.1PL ✓ten sam produkt
OS Command Injection w Dell PowerFlex Manager — wykonanie poleceń jako root
CVE-2024-37143CRITICAL10.0PL ✓ten sam produkt
Krytyczna podatność RCE w produktach Dell PowerFlex, InsightIQ i Data Lakehouse
CVE-2026-56690HIGH8.5PL ✓ten sam produkt
SQL Injection w Dell PowerFlex Manager — ujawnienie danych
CVE-2026-56689HIGH7.7PL ✓ten sam produkt
SQL Injection w Dell PowerFlex Manager — ujawnienie informacji
CVE-2026-35065HIGH8.8ten sam produkt
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function...