Sceawere
Vulnerability Detail
CVE-2026-61421UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Hard-coded Credentials in Dell CSM
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 10h ago
- Vendor
- Dell
- Product
- Container Storage Modules
- Attack Type
- CWE-798: Use of Hard-coded Credentials
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-06T15:17:18.767Z",
"pubdate": "2026-10-06T15:17:18.767Z",
"executiveSummary": "Dell Container Storage Modules (CSM) versions prior to 1.18.0 contain a critical Use of Hard-coded Credentials vulnerability within the CSM Authorization component.\nThis flaw allows an unauthenticated, remote attacker to bypass standard security authentication mechanisms.\nThe primary risk involves unauthorized access to the authorization framework, facilitating potential elevation of privileges within the storage management environment.\nBy leveraging these hard-coded credentials, a malicious actor can gain elevated administrative control over the storage module, potentially compromising data integrity, availability, and confidentiality of storage resources managed by the CSM.\nThe vulnerability does not require prior authentication, making it accessible to any attacker with network connectivity to the affected service endpoint.\nOrganizations using vulnerable versions of Dell CSM are at significant risk of unauthorized administrative takeover and should prioritize remediation efforts to mitigate potential exploitation.",
"technicalDetails": "The vulnerability resides within the CSM Authorization component of the Dell Container Storage Modules. The root cause is the inclusion of static, hard-coded credentials embedded directly within the application's source code or configuration files, rather than utilizing a secure, dynamic, or externally managed authentication scheme.\nIn the context of this vulnerability, the 'hard-coded credential' refers to static authentication tokens or secret keys used to validate requests made to the CSM Authorization service. Because these values are invariant and pre-compiled into the software, they remain consistent across all deployments of the vulnerable versions.\nThe attack flow begins with an attacker identifying the network endpoint associated with the CSM Authorization service. Since the service relies on hard-coded secrets for authentication, the attacker does not need to perform traditional password brute-forcing or credential harvesting. Instead, the attacker initiates a request to the vulnerable service, injecting the discovered or extracted hard-coded credential into the authentication headers or payload parameters.\nUpon receipt of the malicious request, the CSM Authorization component validates the provided credential against the static value stored internally. Because the values match, the service erroneously grants the attacker a session with elevated privileges. This bypasses the intended security architecture, which is designed to require legitimate, provisioned credentials for administrative access.\nExploitation allows the attacker to interact with the API endpoints of the storage module with the same permissions assigned to the hard-coded account. Given that such credentials often possess high-level administrative scope, the attacker can execute unauthorized commands, modify storage configurations, disrupt service operations, or access sensitive backend storage data.\nThe vulnerability affects all versions of Dell Container Storage Modules prior to 1.18.0. The lack of authentication requirements allows for remote exploitation over the network, as the component's reliance on hard-coded secrets effectively negates any access control policies that might otherwise be configured at the network perimeter. The post-exploitation impact is severe, as the attacker effectively assumes the role of an authenticated administrator, allowing for complete control over the storage orchestration logic managed by the CSM Authorization module."
}