Sceawere

Vulnerability Detail

CVE-2026-79684UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell PowerStore Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
Dell
Product
PowerStore 500T
Attack Type
CWE-693: Protection Mechanism Failure
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-01T14:17:41.797Z",
  "pubdate": "2026-09-01T14:17:41.797Z",
  "executiveSummary": "Dell PowerStore is susceptible to a protection mechanism failure vulnerability that permits authenticated users with low-privileged access to circumvent established security boundaries.\nThis vulnerability is classified as a privilege escalation flaw, enabling unauthorized elevation of system rights beyond the scope of a standard user account.\nThe core risk involves the potential for an attacker to perform administrative actions, bypass mandatory access controls, and gain elevated execution capabilities within the storage appliance environment.\nExploitation requires the attacker to possess an established, albeit restricted, authenticated session on the target system.\nThe failure of internal protection mechanisms compromises the integrity and confidentiality of the storage management interface, potentially allowing unauthorized modifications to system configurations, data protection policies, or internal resources.\nGiven that this vulnerability resides within a critical enterprise storage platform, the threat to organizational data security is significant, necessitating immediate review of access controls and firmware update status.",
  "technicalDetails": "The vulnerability manifests as a structural failure in the protection mechanisms governing access control within Dell PowerStore. In standard operation, the platform enforces granular role-based access control (RBAC) to ensure that users operate strictly within their defined privilege levels. The identified flaw indicates that these controls are not strictly enforced during specific request processing cycles.\nThe root cause stems from a flaw in the validation logic of the management plane, which fails to adequately sanitize or re-verify the authorization state of an authenticated user before executing privileged operations. When an authenticated user with limited privileges initiates a specifically crafted request, the system incorrectly evaluates the session authorization context, allowing the request to proceed as if it were initiated by a higher-privileged user.\nThe exploitation process follows a predictable attack flow: First, an attacker establishes a valid, low-privileged session on the Dell PowerStore management interface. Second, the attacker performs service enumeration to identify the specific API endpoints or management functions that lack strict server-side authorization checks. Third, the attacker transmits a crafted payload directed at the identified management functions. Because the protection mechanism fails to perform an intersection between the requested action and the authenticated user's profile, the underlying engine processes the command without secondary validation.\nThe impact of this exploitation is a vertical privilege escalation, where the low-privileged account gains execution rights equivalent to an administrative user. This allows for unauthorized modifications of the storage environment, potential extraction of sensitive management data, or the reconfiguration of protection policies. The vulnerability resides within the appliance's core management software stack. Because the exploitation relies on existing authenticated access, it is considered an internal threat vector that bypasses the intended compartmentalization of administrative duties. The lack of robust integrity checks in the request handler allows for the circumvention of authorization tokens, effectively neutralizing the principle of least privilege within the system architecture."
}