CVE-2026-32657

Summary

Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Affected Software

VendorProductVersion RangeStatus
DellAppSync0 < 4.6.0.4 or lateraffected
DellMetro Node0 < 4.6.0.4 or lateraffected
DellUCC Edge0 < 3.0.2 or lateraffected
DellVxRail0 < 8.0.330 or lateraffected
DellPowerMax0 < 10.3.1.0 Patch 11248 or lateraffected
DellUnity0 < 5.5.2 or lateraffected
DellPowerFlex Manager0 < 4.5.5 or lateraffected
DellPowerFlex Intelligent Catalog0 < 48.383.00 or lateraffected
DellPowerFlex Intelligent Catalog0 < 48.378.00 or lateraffected
DellPowerFlex Rack0 < 4.5.5 or lateraffected

Weaknesses

  • CWE-61: CWE-61: UNIX Symbolic Link (Symlink) Following

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References