Sceawere

Vulnerability Detail

CVE-2026-54489UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell VSI Sensitive Information Disclosure

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
1d ago
Vendor
Dell
Product
Virtual Storage Integrator for VMware vSphere Client
Attack Type
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-06T15:16:56.120Z",
  "pubdate": "2026-08-06T15:16:56.120Z",
  "executiveSummary": "A critical sensitive information disclosure vulnerability exists in Dell Virtual Storage Integrator for VMware vSphere Client, affecting versions prior to 10.11.1.0.\nThe vulnerability allows an unauthenticated remote attacker to harvest active session credentials, directly facilitating unauthorized session hijacking and complete user impersonation.\nGiven that the exploited sessions include administrative privileges, successful exploitation grants the attacker full control over the affected management platform, presenting severe operational and security risks to the virtualized infrastructure.\nThe attack vector is remotely exploitable over the network without requiring prior authentication or user interaction, lowering the complexity barrier for malicious actors.\nDell has identified and addressed this flaw, strongly advising all administrators to apply the necessary upgrades to version 10.11.1.0 or later immediately to eliminate the exposure.",
  "technicalDetails": "The vulnerability resides within Dell Virtual Storage Integrator for VMware vSphere Client versions prior to 10.11.1.0, specifically impacting components handling session management and data exposure.\nThe root cause stems from improper handling and protection of sensitive runtime data, allowing unauthorized external retrieval of active session credentials from the application state.\nAn unauthenticated remote attacker can exploit this weakness by interacting directly with the vulnerable network-exposed endpoints of the application, bypassing standard authentication gates designed to protect session tokens.\nThe attack flow proceeds as follows: First, the remote adversary initiates unauthorized queries against vulnerable interfaces exposed by the software. Second, the application improperly returns sensitive internal state data containing active session tokens or credentials. Third, the attacker extracts these credentials and uses them to forge requests or establish unauthorized sessions.\nUpon successful acquisition of valid session tokens, the payload behavior enables the attacker to completely impersonate legitimate authenticated users, including high-privilege administrative accounts.\nThe post-exploitation impact includes full administrative compromise of the Dell Virtual Storage Integrator environment, enabling arbitrary management operations, manipulation of underlying storage integrations, and potential lateral movement within the integrated VMware vSphere infrastructure.\nPrerequisites for exploitation are limited to network connectivity to the vulnerable Dell Virtual Storage Integrator service endpoints, as no local access, prior credentials, or user interaction are required."
}
CVE-2026-54489: Dell VSI Sensitive Information Disclosure (CRITICAL Severity, CVSS: 9.1) - Sceawere