DSA-2026-234: Security Update for Dell Container Storage Modules Hard-coded Credentials Vulnerability
Shrnutí: Dell Container Storage Modules remediation is available for Dell Container Storage Modules vulnerability that could be exploited by malicious users to compromise the affected system.
Tento článek se vztahuje na
Tento článek se nevztahuje na
Tento článek není vázán na žádný konkrétní produkt.
V tomto článku nejsou uvedeny všechny verze produktu.
Vliv
Critical
Další podrobnosti
This vulnerability exposes hardcoded authentication credentials in public source code repositories, enabling unauthorized access to sensitive system components.
Podrobnosti
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-40710 | Dell Container Storage Modules, versions Operator 1.6.0 through 1.16.3 and Helm Charts 1.11.0 through 1.16.3, contain a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. This vulnerability is considered critical as it exposes default authentication credentials in public source code, enabling unauthorized access to sensitive system components. Attackers can leverage these credentials to compromise authentication sessions, exfiltrate cached data, and potentially pivot to additional services within the infrastructure. The public nature of the exposure means any attacker can immediately obtain and use these credentials without requiring any additional privileges or complex attack techniques. | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-40710 | Dell Container Storage Modules, versions Operator 1.6.0 through 1.16.3 and Helm Charts 1.11.0 through 1.16.3, contain a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. This vulnerability is considered critical as it exposes default authentication credentials in public source code, enabling unauthorized access to sensitive system components. Attackers can leverage these credentials to compromise authentication sessions, exfiltrate cached data, and potentially pivot to additional services within the infrastructure. The public nature of the exposure means any attacker can immediately obtain and use these credentials without requiring any additional privileges or complex attack techniques. | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Dotčené produkty a náprava
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| Dell Container Storage Modules | CSM Operator | Versions 1.6.0 through 1.16.3 | Version 1.17.0 or later | Contact Customer Support |
| Dell Container Storage Modules | CSM Helm Charts | Versions 1.11.0 through 1.16.3 | Version 1.17.0 or later | Contact Customer Support |
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| Dell Container Storage Modules | CSM Operator | Versions 1.6.0 through 1.16.3 | Version 1.17.0 or later | Contact Customer Support |
| Dell Container Storage Modules | CSM Helm Charts | Versions 1.11.0 through 1.16.3 | Version 1.17.0 or later | Contact Customer Support |
Historie změn
| Revision | Date | Description |
| 1.0 | 2026-05-21 | Initial Release |
Související informace
Právní upozornění
Dotčené produkty
Container Storage Modules Family, Container Storage ModulesVlastnosti článku
Číslo článku: 000467149
Typ článku: Dell Security Advisory
Poslední úprava: 21 kvě 2026
Najděte odpovědi na své otázky od ostatních uživatelů společnosti Dell
Služby podpory
Zkontrolujte, zda se na vaše zařízení vztahují služby podpory.