Sceawere

Vulnerability Detail

CVE-2026-54472UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell CSM Hard-coded Credentials Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
10h ago
Vendor
Dell
Product
Container Storage Modules
Attack Type
CWE-798: Use of Hard-coded Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-06T15:17:18.483Z",
  "pubdate": "2026-10-06T15:17:18.483Z",
  "executiveSummary": "Dell Container Storage Modules (CSM) versions prior to 1.18.0 contain a critical Use of Hard-coded Credentials vulnerability identified within the csm-docs component.\nThis security flaw allows an unauthenticated, remote attacker to gain unauthorized access to sensitive information protected by these credentials.\nThe vulnerability poses a severe risk to the confidentiality of the storage management environment, as the exposure of hard-coded secrets often facilitates lateral movement or further unauthorized system interaction.\nExploitation does not require prior authentication, significantly lowering the barrier to entry for malicious actors targeting Dell storage infrastructure.\nThe impact is characterized by unauthorized information disclosure, which could lead to the compromise of broader storage orchestrator configurations or administrative access depending on the scope of the exposed credentials.\nOrganizations deploying Dell CSM are urged to assess their current versioning and prioritize remediation to prevent exploitation of this static credential exposure.",
  "technicalDetails": "The vulnerability originates from the inclusion of hard-coded credentials within the csm-docs component of the Dell Container Storage Modules. In software engineering, the practice of embedding credentials—such as API keys, passwords, or authentication tokens—directly into source code, configuration files, or documentation is considered a critical security anti-pattern.\nRoot Cause: The csm-docs component contains static, immutable credentials that are deployed alongside the application binaries. Because these credentials are not generated dynamically or retrieved via secure secret management vaults at runtime, they remain identical across all installations of the affected versions.\nAffected Versions: All instances of Dell Container Storage Modules prior to version 1.18.0 are susceptible to this exposure. The vulnerability is tied specifically to the distributed documentation and supporting artifacts within the containerized environment.\nAttack Flow: An attacker can exploit this vulnerability by accessing the publicly available or reachable csm-docs path within the containerized deployment. Since the credentials are hard-coded, the attacker does not need to perform brute-force attacks or sophisticated reconnaissance. Upon accessing the documentation or associated configuration files, the attacker can extract the plaintext credentials.\nAuthentication/Privilege Requirements: The vulnerability is exploitable by an unauthenticated remote attacker. No specialized privileges are required to access the exposed data, as the credentials reside in a location that is often inadvertently exposed or accessible through standard network-facing services associated with the CSM deployment.\nPost-Exploitation Impact: Once the hard-coded credentials are obtained, the attacker can leverage them to authenticate against internal storage services or management interfaces that utilize these secrets for authorization. This leads to unauthorized information disclosure, potentially exposing internal architecture, storage volume details, or metadata. If the exposed credentials grant higher-level permissions, the attacker might escalate their access within the Kubernetes cluster or the underlying Dell storage arrays, facilitating further data exfiltration or management disruption. The lack of dynamic credential rotation means that changing these secrets requires an administrative intervention or a patch update, leaving the system vulnerable until the underlying code is corrected."
}
CVE-2026-54472: Dell CSM Hard-coded Credentials Vulnerability (CRITICAL Severity, CVSS: 9.8) | Sceawere