cbcvebase.

Dell Powerstore vulnerabilities

23 known vulnerabilities affecting dell/powerstore.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH10MEDIUM10

Vulnerabilities

Page 1 of 2
CVE-2022-31234P2CRITICALCVSS 9.8≥ unspecified, < v3.0.0.02022-07-21
CVE-2022-31234 [CRITICAL] CWE-307 CVE-2022-31234: Dell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnera Dell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing. Account takeover is possible if weak passwords are used by users.
nvd
CVE-2022-26870P2CRITICALCVSS 9.8≥ unspecified, < 2.1.x2022-10-21
CVE-2022-26870 [CRITICAL] CWE-288 CVE-2022-26870: Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenti Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon successful exploit.
nvd
CVE-2022-26869P3CRITICALCVSS 9.8≥ unspecified, < 2.0.0.x, 2.0.1.x, and 2.1.0.x2022-06-02
CVE-2022-26869 [CRITICAL] CWE-200 CVE-2022-26869: Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and arbitrary code execution.
nvd
CVE-2022-33923P3HIGHCVSS 7.8≥ unspecified, < 3.0.0.02022-07-21
CVE-2022-33923 [HIGH] CWE-78 CVE-2022-33923: Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerS Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.
nvd
CVE-2022-26868P3HIGHCVSS 7.8≥ unspecified, < PowerStore SW v2.1.1.02022-06-02
CVE-2022-26868 [HIGH] CWE-78 CVE-2022-26868: Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection fla Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system takeover
nvd
CVE-2022-22557P3HIGHCVSS 7.8≥ unspecified, < PowerStore SW v2.1.0.0-15534192022-06-02
CVE-2022-22557 [HIGH] CWE-256 CVE-2022-22557: PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments runni PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable applic
nvd
CVE-2022-22556P3HIGHCVSS 7.5≥ unspecified, < PowerStore SW v2.1.0.02022-06-02
CVE-2022-22556 [HIGH] CWE-400 CVE-2022-22556: Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Inter Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the Denial of Service.
nvd
CVE-2020-5372P3HIGHCVSS 7.5≥ unspecified, < 1.0.1.0.5.0022020-07-06
CVE-2020-5372 [HIGH] CWE-1244 CVE-2020-5372: Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interf Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potentially cause Denial of Service via test interface ports which are not used during run time environment.
nvd
CVE-2025-36572P3MEDIUMCVSS 6.5≥ N/A, < 4.0.1.3-24941472025-05-28
CVE-2025-36572 [MEDIUM] CWE-798 CVE-2025-36572: Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in th Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges.
nvd
CVE-2022-26867P3HIGHCVSS 8.0≥ unspecified, < PowerStore SW v2.1.1.02022-06-02
CVE-2022-26867 [HIGH] CWE-1236 CVE-2022-26867: PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.
nvd
CVE-2022-32498P3HIGHCVSS 7.8≥ unspecified, < v3.0.0.02022-07-21
CVE-2022-32498 [HIGH] CWE-427 CVE-2022-32498: Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A l Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit this vulnerability to execute arbitrary code, escalate privileges, and bypass software allow list solutions, leading to system takeover or IP exposure.
nvd
CVE-2023-32449P4HIGHCVSS 7.8vVersions prior to 3.5.0.0-20503212023-06-22
CVE-2023-32449 [HIGH] CWE-347 CVE-2023-32449: Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature v Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks
nvd
CVE-2024-51532P4HIGHCVSS 7.1≥ N/A, < 4.0.1.0-24082342024-12-19
CVE-2024-51532 [HIGH] CWE-88 CVE-2024-51532: Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument I Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
nvd
CVE-2026-28265P4HIGHCVSS 7.1fixed in 4.4.0.0-2692403 or later2026-04-01
CVE-2026-28265 [HIGH] CWE-35 CVE-2026-28265: PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker w PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
nvd
CVE-2020-29499P4MEDIUMCVSS 6.7≥ unspecified, < PowerStore SW 1.0.3.0.5.0062021-07-19
CVE-2020-29499 [MEDIUM] CWE-78 CVE-2020-29499: Dell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in Dell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in PowerStore X environment . A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.
nvd
CVE-2022-22555P4MEDIUMCVSS 6.7≥ unspecified, < X and T models2022-07-21
CVE-2022-22555 [MEDIUM] CWE-78 CVE-2022-22555: Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacke Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the PowerStore underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.
nvd
CVE-2020-29502P4MEDIUMCVSS 6.7≥ unspecified, < PowerStore SW 1.0.3.0.5.0062021-01-05
CVE-2020-29502 [MEDIUM] CWE-312 CVE-2020-29502: Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerabil Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerabl
nvd
CVE-2020-29500P4MEDIUMCVSS 6.7≥ unspecified, < PowerStore SW 1.0.3.0.5.0062021-01-05
CVE-2020-29500 [MEDIUM] CWE-312 CVE-2020-29500: Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerabil Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable ap
nvd
CVE-2020-29501P4MEDIUMCVSS 6.7≥ unspecified, < PowerStore SW 1.0.3.0.5.0062021-01-05
CVE-2020-29501 [MEDIUM] CWE-312 CVE-2020-29501: Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerabil Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerabl
nvd
CVE-2024-30476P4MEDIUMCVSS 5.4fixed in 4.0.0.0-2284811 or later2026-06-16
CVE-2024-30476 [MEDIUM] CWE-79 CVE-2024-30476: PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-privileged malicious actor could potentially exploit this vulnerability, it could lead to script execution in the client browser.
nvd
Dell Powerstore vulnerabilities | cvebase