Sceawere

Vulnerability Detail

CVE-2026-63691UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell CSI Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
9h ago
Vendor
Dell
Product
Container Storage Modules
Attack Type
CWE-862: Missing Authorization
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-10-06T16:17:09.187Z",
  "pubdate": "2026-10-06T16:17:09.187Z",
  "executiveSummary": "Dell Container Storage Modules (CSM) versions prior to 1.18.0 are susceptible to a critical Missing Authorization vulnerability located within the csireverseproxy component of the Dell CSI Driver for PowerMax.\nThe vulnerability allows an unauthenticated, adjacent network-based attacker to bypass established security controls, resulting in unauthorized access to sensitive storage management functions.\nBy failing to validate the authorization context of incoming requests, the affected component permits malicious actors to interface with restricted operations that should otherwise be protected by strict authentication mechanisms.\nThis flaw presents significant risk to the integrity and availability of storage infrastructure managed by the CSI driver, as an attacker could potentially gain unauthorized control over storage resources.\nSuccessful exploitation requires the attacker to have adjacent network access to the target environment, which serves as a primary constraint for potential threat actors.",
  "technicalDetails": "The vulnerability stems from a flaw in the authorization logic within the csireverseproxy component of the Dell CSI Driver for PowerMax. In versions prior to 1.18.0, the proxy fails to properly verify or enforce authentication headers and authorization tokens when processing incoming API requests directed at the storage management interface.\nThe root cause is identified as a missing authorization check, which allows the proxy to forward requests to the underlying storage management plane without confirming that the requesting entity holds the appropriate permissions or valid credentials.\nThe exploitation flow begins with an attacker positioned on the adjacent network, capable of routing traffic to the address where the csireverseproxy is exposed. The attacker constructs malicious HTTP requests that are designed to interact with the PowerMax management API via the proxy. Because the proxy does not perform the necessary authorization validation, the payload is transparently proxied to the target system.\nThe affected component, csireverseproxy, acts as a bridge between the Kubernetes container storage interface and the PowerMax storage backend. By bypassing this proxy's security layer, an attacker can effectively execute arbitrary management commands that the driver is configured to permit. This behavior grants the attacker unauthorized access to storage provisioning and configuration operations.\nPost-exploitation, the impact is significant; an unauthorized actor could potentially perform storage provisioning tasks, modify logical unit numbers (LUNs), or access sensitive metadata managed through the driver. This unauthorized access compromises the confidentiality and availability of the storage array, as the lack of authentication allows for unmediated interaction with administrative interfaces.\nThe vulnerability is confined to instances where the Dell CSI Driver for PowerMax is deployed utilizing the csireverseproxy module. Since the authorization failure occurs at the proxy level rather than the target storage backend itself, the exposure is limited to requests mediated through the vulnerable proxy component. No specific privilege elevation is required if the proxy does not demand session-based tokens prior to request forwarding."
}
CVE-2026-63691: Dell CSI Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 6.1) | Sceawere