Dell Powerstoreos vulnerabilities
11 known vulnerabilities affecting dell/powerstoreos.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2022-26870P2CRITICALCVSS 9.8v2.1.0.0v2.1.0.12022-10-21
CVE-2022-26870 [CRITICAL] CWE-288 CVE-2022-26870: Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenti
Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon successful exploit.
nvd
CVE-2022-26869P3CRITICALCVSS 9.8≥ 2.0.0.0, < 2.1.1.02022-06-02
CVE-2022-26869 [CRITICAL] CWE-200 CVE-2022-26869: Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote
Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and arbitrary code execution.
nvd
CVE-2022-26868P3HIGHCVSS 7.8≥ 2.0.0.0, < 2.1.1.02022-06-02
CVE-2022-26868 [HIGH] CWE-78 CVE-2022-26868: Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection fla
Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system takeover
nvd
CVE-2022-22557P3HIGHCVSS 7.8≥ 2.0.0.0, < 2.1.0.0≥ 2.0.0.0, < 2.1.1.02022-06-02
CVE-2022-22557 [HIGH] CWE-256 CVE-2022-22557: PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments runni
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable applic
nvd
CVE-2022-22556P3HIGHCVSS 7.5fixed in 2.1.0.0fixed in 2.1.1.02022-06-02
CVE-2022-22556 [HIGH] CWE-400 CVE-2022-22556: Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Inter
Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the Denial of Service.
nvd
CVE-2025-36572P3MEDIUMCVSS 6.5fixed in 4.0.1.3-24941472025-05-28
CVE-2025-36572 [MEDIUM] CWE-798 CVE-2025-36572: Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in th
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges.
nvd
CVE-2022-26867P3HIGHCVSS 8.0fixed in 2.1.1.02022-06-02
CVE-2022-26867 [HIGH] CWE-1236 CVE-2022-26867: PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data
PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.
nvd
CVE-2024-51532P4HIGHCVSS 7.1fixed in 4.0.1.0-24082342024-12-19
CVE-2024-51532 [HIGH] CWE-88 CVE-2024-51532: Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument I
Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
nvd
CVE-2026-28265P4HIGHCVSS 7.1fixed in 4.4.0.0-26924032026-04-01
CVE-2026-28265 [HIGH] CWE-35 CVE-2026-28265: PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker w
PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
nvd
CVE-2022-26866P4MEDIUMCVSS 5.5fixed in 2.1.1.02022-06-02
CVE-2022-26866 [MEDIUM] CWE-79 CVE-2022-26866: Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A hi
Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged network attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malici
nvd
CVE-2023-32478P4MEDIUMCVSS 4.9fixed in 3.5.0.12023-07-21
CVE-2023-32478 [MEDIUM] CWE-532 CVE-2023-32478: Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log fi
Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exploit this vulnerability, leading to sensitive information disclosure.
nvd