CVE-2026-67270: High severity Dell Container Storage Modules (CSM) vulnerability
Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Container Storage Modules (CSM)to a version that resolves this vulnerability.Fixed in 1.18.0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Dell Container Storage Modules deployments using versions earlier than 1.18.0 are affected, specifically through the proxy-server component.
What does an attacker need to exploit the vulnerability?
The attacker must be on an adjacent network and does not need authentication or user interaction. Exploitation is rated as high complexity.
What information could be exposed?
Successful exploitation could expose administrator credentials for the storage backend.
What version remediates the issue?
Update Dell Container Storage Modules to version 1.18.0 or later.