Sceawere

Vulnerability Detail

CVE-2026-76105UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Insufficient Randomness in Dell CSM

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
9h ago
Vendor
Dell
Product
Container Storage Modules
Attack Type
CWE-330: Use of Insufficiently Random Values
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-10-06T16:17:10.000Z",
  "pubdate": "2026-10-06T16:17:10.000Z",
  "executiveSummary": "Dell Container Storage Modules (CSM) versions prior to 1.18.0 are susceptible to a vulnerability involving the Use of Insufficiently Random Values.\nThis vulnerability stems from the generation of predictable data, which undermines security mechanisms that rely on cryptographic entropy.\nAn unauthenticated attacker possessing local access to the host environment can exploit this flaw to compromise the integrity of information managed by the modules.\nThe primary risk implication is Information tampering, where an attacker can influence or modify sensitive data processed or stored by the affected system.\nSuccessful exploitation requires the attacker to have pre-existing local access, limiting the attack surface to malicious actors already positioned within the container infrastructure or the underlying host operating system.\nThere is no requirement for network-based interaction, as the attack vector is localized to the interaction between the attacker and the vulnerable CSM components.",
  "technicalDetails": "The vulnerability, classified under the Use of Insufficiently Random Values, indicates that the affected Dell Container Storage Modules utilize a weak or deterministic entropy source for generating sensitive security parameters or tokens.\nIn standard cryptographic operations, the security of the implementation relies heavily on the quality of the Pseudo-Random Number Generator (PRNG). When the PRNG lacks sufficient entropy or is improperly initialized, the resulting 'random' values become predictable to an observer with sufficient insight into the system state.\nThe root cause is identified as an implementation flaw in the module's generation logic, likely involving the use of insecure system calls or non-cryptographically secure random number generators (CSPRNGs) when producing values for session IDs, tokens, or cryptographic salts.\nThe attack flow requires an unauthenticated local attacker to observe or estimate the output of the insufficient randomness generator. Because the values are not sufficiently random, the attacker can leverage mathematical modeling or brute-force state prediction to determine subsequent values generated by the system.\nOnce the attacker successfully predicts or reproduces these insufficiently random values, they can forge credentials, intercept or manipulate session-specific data, or perform unauthorized state transitions that lead to Information tampering.\nBecause the vulnerability exists at the module level, the impact is localized to the data handled by the Dell Container Storage Modules. An attacker, having established local access to the container host or a sidecar container, can monitor the generation process and perform local injection or manipulation of the data streams managed by the modules.\nThe lack of sufficient entropy implies that any security controls predicated on these values, such as authentication tokens or request integrity checks, are effectively bypassed. This allows the attacker to manipulate configurations, modify storage metadata, or perform unauthorized operations that the system assumes to be legitimate due to the presence of the 'randomly' generated but actually predictable identifier.\nAffected versions are strictly limited to those identified as prior to 1.18.0. Post-exploitation, the attacker gains the ability to tamper with system information, which could lead to further escalation of privilege or unauthorized persistence within the container storage environment."
}
CVE-2026-76105: Insufficient Randomness in Dell CSM (HIGH Severity, CVSS: 7.7) | Sceawere