Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NDell Powerflex Manager
APPDell4.5.5 – 4.5.5.2 (excl.)5.1.0 – 5.1.0.1 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
CWE
Related vulnerabilities
CVE-2026-56688CRITICAL9.1PL ✓same product
OS Command Injection w Dell PowerFlex Manager — wykonanie poleceń jako root
CVE-2024-37143CRITICAL10.0PL ✓same product
Krytyczna podatność RCE w produktach Dell PowerFlex, InsightIQ i Data Lakehouse
CVE-2026-56690HIGH8.5PL ✓same product
SQL Injection w Dell PowerFlex Manager — ujawnienie danych
CVE-2026-32804HIGH8.1same product
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An u...
CVE-2026-22283HIGH7.5same product
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted C...