CVE-2026-32657
7.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Summary
Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Dell | AppSync | 0 < 4.6.0.4 or later | affected |
| Dell | Metro Node | 0 < 4.6.0.4 or later | affected |
| Dell | UCC Edge | 0 < 3.0.2 or later | affected |
| Dell | VxRail | 0 < 8.0.330 or later | affected |
| Dell | PowerMax | 0 < 10.3.1.0 Patch 11248 or later | affected |
| Dell | Unity | 0 < 5.5.2 or later | affected |
| Dell | PowerFlex Manager | 0 < 4.5.5 or later | affected |
| Dell | PowerFlex Intelligent Catalog | 0 < 48.383.00 or later | affected |
| Dell | PowerFlex Intelligent Catalog | 0 < 48.378.00 or later | affected |
| Dell | PowerFlex Rack | 0 < 4.5.5 or later | affected |
Weaknesses
- CWE-61: CWE-61: UNIX Symbolic Link (Symlink) Following
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.