HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2026-35065

CVSS 8.8v3.1pub. 2026-06-17upd. 2026-06-25

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Information tampering, Remote execution, Script injection, and Unauthorized access.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dell Powerflex Manager

    APP
    Dell
    < 4.5.5.24.6.0 – 5.1.0.1 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEAuth BypassDoS
CWE
References

Related vulnerabilities

CVE-2026-56688CRITICAL9.1PL ✓same product

OS Command Injection w Dell PowerFlex Manager — wykonanie poleceń jako root

CVE-2024-37143CRITICAL10.0PL ✓same product

Krytyczna podatność RCE w produktach Dell PowerFlex, InsightIQ i Data Lakehouse

CVE-2026-56690HIGH8.5PL ✓same product

SQL Injection w Dell PowerFlex Manager — ujawnienie danych

CVE-2026-56689HIGH7.7PL ✓same product

SQL Injection w Dell PowerFlex Manager — ujawnienie informacji

CVE-2026-32804HIGH8.1same product

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An u...