Inclusion of Functionality from Untrusted Control Sphere in Dell PowerFlex Manager
CVE-2026-22283

7.5HIGH

Key Information:

Vendor

Dell

Status
Vendor
CVE Published:
17 June 2026

What is CVE-2026-22283?

Dell PowerFlex Manager versions prior to 4.8 are susceptible to a vulnerability that allows unauthenticated remote attackers to exploit the system. By exploiting this weakness, attackers may gain unauthorized access, leading to potential information disclosures that could compromise sensitive data. It is essential for users to upgrade to the latest version to mitigate this risk and enhance system security.

Affected Version(s)

PowerFlex 0 < 5.1.0.1 or later

PowerFlex 0 < 4.5.5.2 or later

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.