Dell Unisphere for PowerMax Virtual Appliance Static Code Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A static code injection vulnerability has been identified in Dell Unisphere for PowerMax virtual appliance, specifically in version 9.2.4.x. This vulnerability arises from improper neutralization of directives in statically saved code. A high-privileged attacker with remote access could exploit this issue, potentially leading to unauthorized code execution.

Impact

Exploitation of this vulnerability could result in unauthorized code execution on the affected system.

Remediation

Users can upgrade to version 9.2.4.17 or later to address this vulnerability. Instructions for downloading the update are available on the Dell Unisphere for PowerMax product support page.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.