Sceawere
Vulnerability Detail
CVE-2026-63690UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell CSM Authentication Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 9h ago
- Vendor
- Dell
- Product
- Container Storage Modules
- Attack Type
- CWE-306: Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability in the csi-powerflex; csi-powermax; csi-powerstore. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-06T16:17:09.060Z",
"pubdate": "2026-10-06T16:17:09.060Z",
"executiveSummary": "Dell Container Storage Modules (CSM) versions prior to 1.18.0 are susceptible to a Missing Authentication for Critical Function vulnerability.\nThis vulnerability affects specific storage drivers: csi-powerflex, csi-powermax, and csi-powerstore.\nAn unauthenticated, adjacent network attacker can exploit this flaw to bypass established security controls.\nSuccessful exploitation results in unauthorized information disclosure, potentially exposing sensitive configuration data or internal operational metrics.\nThe risk is categorized by the requirement for adjacent network access, which limits the immediate exposure to local segments, though it represents a significant failure in the authentication architecture of the storage management interface.",
"technicalDetails": "The vulnerability originates from a Missing Authentication for Critical Function flaw within the administrative or management API endpoints of the affected Dell Container Storage Modules. In versions prior to 1.18.0, the csi-powerflex, csi-powermax, and csi-powerstore modules fail to enforce cryptographic or identity-based validation for requests directed at specific internal functions.\nThe root cause is an improper authorization check during the request-handling lifecycle, allowing the underlying application logic to process sensitive queries without validating the requestor's identity or authorization token. Because the service does not strictly enforce authentication, any actor within the same broadcast domain or network segment can issue direct requests to these endpoints.\nThe attack flow begins with an attacker performing service discovery to identify the specific API endpoints managed by the CSI drivers. Once identified, the attacker crafts unauthenticated requests—typically HTTP GET or similar methods—targeting the vulnerable functions. Because the system lacks a secondary check, the service processes these requests and returns sensitive data that should be restricted to authenticated administrators.\nThe vulnerable components are the integration modules for Dell PowerFlex, PowerMax, and PowerStore. Since these modules operate within a Kubernetes ecosystem, the exploit occurs at the pod/service level, bypassing the intended security boundaries of the storage plugin framework. The lack of authentication effectively bypasses the Principle of Least Privilege, as the application assumes that any communication originates from a trusted internal source within the orchestrator environment.\nThe post-exploitation impact is limited primarily to Information Disclosure. By successfully querying the unauthenticated endpoints, an attacker may retrieve configuration parameters, metadata, or performance statistics that could be leveraged for further reconnaissance within the storage subsystem. This could facilitate more advanced attacks, such as identifying backend infrastructure details or mapping the storage topology for targeted disruption in subsequent phases. There is no requirement for high-level privileges; the vulnerability is accessible to any entity capable of sending traffic to the vulnerable service interface from an adjacent network location."
}