CVE-2026-67271

Summary

Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for Remote Code execution.

Affected Software

VendorProductVersion RangeStatus
DellPowerStore 500T0 < 5.0.0.2-2761110 or lateraffected
DellPowerStore 1000T0 < 5.0.0.2-2761110 or lateraffected
DellPowerStore 1200T0 < 5.0.0.2-2761110 or lateraffected
DellPowerStore 3000T0 < 5.0.0.2-2761110 or lateraffected
DellPowerStore 3200Q0 < 5.0.0.2-2761110 or lateraffected
DellPowerStore 3200T0 < 5.0.0.2-2761110 or lateraffected
DellPowerStore 5000T0 < 5.0.0.2-2761110 or lateraffected
DellPowerStore 5200Q0 < 5.0.0.2-2761110 or lateraffected
DellPowerStore 5200T0 < 5.0.0.2-2761110 or lateraffected
DellPowerStore 7000T0 < 5.0.0.2-2761110 or lateraffected
DellPowerStore 9000T0 < 5.0.0.2-2761110 or lateraffected
DellPowerStore 9200T0 < 5.0.0.2-2761110 or lateraffected

Weaknesses

  • CWE-787: CWE-787: Out-of-bounds Write

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References