CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-56688

CVSS 9.1v3.1pub. 2026-07-10upd. 2026-07-16

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary command execution as root, potentially leading to full appliance compromise and lateral movement into managed infrastructure.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Dell Powerflex Manager

    APP
    Dell
    4.5.5 – 4.5.5.2 (excl.)5.1.0 – 5.1.0.1 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2024-37143CRITICAL10.0PL ✓same product

Krytyczna podatność RCE w produktach Dell PowerFlex, InsightIQ i Data Lakehouse

CVE-2026-56689HIGH7.7PL ✓same product

SQL Injection w Dell PowerFlex Manager — ujawnienie informacji

CVE-2026-56690HIGH8.5PL ✓same product

SQL Injection w Dell PowerFlex Manager — ujawnienie danych

CVE-2026-32804HIGH8.1same product

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An u...

CVE-2026-22283HIGH7.5same product

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted C...