CVE-2026-63690: Medium severity Dell Container Storage Modules vulnerability
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability in the csi-powerflex; csi-powermax; csi-powerstore. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Container Storage Modulesto a version that resolves this vulnerability.Fixed in 1.18.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Dell Container Storage Modules deployments using csi-powerflex, csi-powermax, or csi-powerstore are affected if they run a version earlier than 1.18.0. Exploitation requires adjacent network access.
Does an attacker need credentials or user interaction?
No. The vulnerability is described as exploitable by an unauthenticated attacker, and the vector indicates no privileges or user interaction are required.
What is the known impact?
Successful exploitation could lead to information disclosure. The supplied vector also indicates a low availability impact, while integrity impact is listed as none.