Dell PowerStore Hard-Coded Credentials Vulnerability Allowing Unauthorized Access

Vulnerability

A vulnerability exists in Dell PowerStore version 4.0.0.0, related to the use of hard-coded credentials in the PowerStore image file. This vulnerability allows a low-privileged attacker with remote access and knowledge of the hard-coded credentials to gain unauthorized access, depending on the privileges associated with the hard-coded account.

Impact

Exploitation of this vulnerability could lead to unauthorized access on the affected system, based on the privileges of the hard-coded account.

Remediation

Users can upgrade to Dell PowerStore version 4.0.1.3-2494147 to address this vulnerability. Instructions for downloading the update are available on the Dell PowerStore 500T, 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 5200T, 7000T, 9000T, and 9200T product support pages.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
5.2
remediation
7.7
relevance
0.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.