Sceawere
Vulnerability Detail
CVE-2026-76105UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Insufficient Randomness in Dell CSM
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.7
- Creation Date
- 9h ago
- Vendor
- Dell
- Product
- Container Storage Modules
- Attack Type
- CWE-330: Use of Insufficiently Random Values
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.7",
"pubDate": "2026-10-06T16:17:10.000Z",
"pubdate": "2026-10-06T16:17:10.000Z",
"executiveSummary": "Dell Container Storage Modules (CSM) versions prior to 1.18.0 are susceptible to a vulnerability involving the Use of Insufficiently Random Values.\nThis vulnerability stems from the generation of predictable data, which undermines security mechanisms that rely on cryptographic entropy.\nAn unauthenticated attacker possessing local access to the host environment can exploit this flaw to compromise the integrity of information managed by the modules.\nThe primary risk implication is Information tampering, where an attacker can influence or modify sensitive data processed or stored by the affected system.\nSuccessful exploitation requires the attacker to have pre-existing local access, limiting the attack surface to malicious actors already positioned within the container infrastructure or the underlying host operating system.\nThere is no requirement for network-based interaction, as the attack vector is localized to the interaction between the attacker and the vulnerable CSM components.",
"technicalDetails": "The vulnerability, classified under the Use of Insufficiently Random Values, indicates that the affected Dell Container Storage Modules utilize a weak or deterministic entropy source for generating sensitive security parameters or tokens.\nIn standard cryptographic operations, the security of the implementation relies heavily on the quality of the Pseudo-Random Number Generator (PRNG). When the PRNG lacks sufficient entropy or is improperly initialized, the resulting 'random' values become predictable to an observer with sufficient insight into the system state.\nThe root cause is identified as an implementation flaw in the module's generation logic, likely involving the use of insecure system calls or non-cryptographically secure random number generators (CSPRNGs) when producing values for session IDs, tokens, or cryptographic salts.\nThe attack flow requires an unauthenticated local attacker to observe or estimate the output of the insufficient randomness generator. Because the values are not sufficiently random, the attacker can leverage mathematical modeling or brute-force state prediction to determine subsequent values generated by the system.\nOnce the attacker successfully predicts or reproduces these insufficiently random values, they can forge credentials, intercept or manipulate session-specific data, or perform unauthorized state transitions that lead to Information tampering.\nBecause the vulnerability exists at the module level, the impact is localized to the data handled by the Dell Container Storage Modules. An attacker, having established local access to the container host or a sidecar container, can monitor the generation process and perform local injection or manipulation of the data streams managed by the modules.\nThe lack of sufficient entropy implies that any security controls predicated on these values, such as authentication tokens or request integrity checks, are effectively bypassed. This allows the attacker to manipulate configurations, modify storage metadata, or perform unauthorized operations that the system assumes to be legitimate due to the presence of the 'randomly' generated but actually predictable identifier.\nAffected versions are strictly limited to those identified as prior to 1.18.0. Post-exploitation, the attacker gains the ability to tamper with system information, which could lead to further escalation of privilege or unauthorized persistence within the container storage environment."
}