Sceawere

Vulnerability Detail

CVE-2026-61411UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell CSM Log Information Disclosure

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
9h ago
Vendor
Dell
Product
Container Storage Modules
Attack Type
CWE-532: Insertion of Sensitive Information into Log File
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-10-06T16:17:08.693Z",
  "pubdate": "2026-10-06T16:17:08.693Z",
  "executiveSummary": "Dell Container Storage Modules (CSM) versions prior to 1.18.0 are susceptible to an Insertion of Sensitive Information into Log File vulnerability.\nThe vulnerability arises from the improper handling of sensitive data during logging operations, which results in the exposure of protected information within application log files.\nAn attacker possessing low-privileged remote access to the environment can leverage this vulnerability to gain unauthorized visibility into sensitive data contained within these logs.\nThe primary impact of this flaw is unauthorized information disclosure, which could lead to the exposure of credentials, configuration secrets, or operational data that may facilitate further exploitation of the storage infrastructure.\nThis vulnerability represents a significant security risk for containerized environments relying on Dell CSM, as log files are often accessible to automated monitoring tools or log aggregation services, potentially broadening the scope of the exposure.\nExploitation requires the attacker to have at least low-privileged remote access to the system where the logs are generated or stored, making the security of log management infrastructure a critical component of the risk profile.",
  "technicalDetails": "The vulnerability, classified as an Insertion of Sensitive Information into Log File, stems from insecure logging practices within the Dell Container Storage Modules (CSM).\nRoot Cause Analysis: The underlying defect exists within the module's instrumentation or debugging logic, which fails to sanitize or redact sensitive parameters, authentication tokens, or internal system metadata before writing entries to the standard output or diagnostic files. Consequently, these transient secrets are persisted in plaintext within the log stream.\nAttack Flow: The exploitation lifecycle initiates when an attacker with low-privileged remote access targets the node or the centralized log management system (e.g., Fluentd, ELK stack, or CloudWatch) that ingests the Dell CSM container logs. Because the application logic does not implement data masking or encryption for its logs, the sensitive information becomes a permanent fixture of the persistent storage layer used for auditing.\nThe attacker observes the log output during routine operations or triggers specific, non-privileged functional requests that force the module to generate logs containing the sensitive data. By accessing the log aggregation interface or local log files through compromised service accounts or exposed API endpoints, the attacker retrieves the leaked information.\nAuthentication and Privilege Requirements: The exploit requires the attacker to have already established low-privileged remote access to the environment. While the vulnerability does not allow for direct code execution or privilege escalation within the module itself, it acts as a critical information vector that provides the attacker with the necessary context—such as session tokens, backend credentials, or infrastructure topology—to move laterally or target more sensitive components within the storage stack.\nPost-Exploitation Impact: Successful exploitation leads to the breach of confidentiality regarding storage module operations. Given that CSM often manages interactions with underlying storage arrays, the leaked information may include administrative keys or sensitive API access identifiers, significantly lowering the barrier for full control of the storage subsystem. The lack of granular access control on log files exacerbates this risk, as log access is often less restricted than the actual management interfaces of the storage arrays themselves."
}
CVE-2026-61411: Dell CSM Log Information Disclosure (HIGH Severity, CVSS: 7.7) | Sceawere