Sceawere
Vulnerability Detail
CVE-2026-67271UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell PowerStore SDNAS SMB Out-of-Bounds Write Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 2h ago
- Vendor
- Dell
- Product
- PowerStore 500T
- Attack Type
- CWE-787: Out-of-bounds Write
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for Remote Code execution.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-08-18T17:17:00.973Z",
"pubdate": "2026-08-18T17:17:00.973Z",
"executiveSummary": "An Out-of-Bounds Write vulnerability exists within the SMB/CIFS component of Dell PowerStore SDNAS. This critical security flaw allows unauthenticated remote attackers to interact with the vulnerable service over the network, posing severe risks to system availability and integrity. Successful exploitation of this vulnerability can result in a Denial of Service condition, characterized by system crashes that persist if automatic restarts are enabled, as well as potential Remote Code Execution under specific, sophisticated exploitation scenarios. The attack vector requires network access to the target system and the transmission of a specially crafted Server Message Block packet, eliminating the need for prior authentication or elevated privileges. Given the severity of the potential impact—ranging from operational disruption to complete system compromise—this vulnerability represents a critical risk to enterprise environments utilizing Dell PowerStore SDNAS. Remediation requires prompt application of vendor-supplied patches or adherence to official security advisories to mitigate exposure to unauthenticated remote threats.",
"technicalDetails": "The vulnerability is classified as an Out-of-Bounds Write, residing in the SMB/CIFS protocol implementation of Dell PowerStore SDNAS. The root cause stems from improper boundary checking and memory management when processing incoming Server Message Block packets containing malformed or malicious data structures. The vulnerable component fails to adequately validate the size and offset parameters specified within the packet payload prior to performing memory write operations.\nExploitation occurs via the network protocol layer without requiring user interaction, authentication, or privileged access. An unauthenticated remote attacker initiates the attack flow by constructing a specially crafted SMB packet designed to manipulate memory allocation and exceed the bounds of the allocated buffer. Upon receipt, the SMB/CIFS service processes the malformed packet, triggering the Out-of-Bounds Write condition.\nThe immediate payload behavior results in memory corruption, which subsequently manifests as a service or system crash. In environments where automatic service or system restarts are configured, the crash condition becomes persistent, leading to a prolonged or repeated Denial of Service state. Furthermore, in more sophisticated attack scenarios, a threat actor can leverage the precise memory corruption primitive achieved via the Out-of-Bounds Write to execute arbitrary code within the context of the vulnerable application, thereby achieving Remote Code Execution."
}