DSA-2026-234: Security Update for Dell Container Storage Modules Hard-coded Credentials Vulnerability
Oversigt: Dell Container Storage Modules remediation is available for Dell Container Storage Modules vulnerability that could be exploited by malicious users to compromise the affected system.
Denne artikel gælder for
Denne artikel gælder ikke for
Denne artikel er ikke knyttet til et bestemt produkt.
Det er ikke alle produktversioner, der er identificeret i denne artikel.
Virkning
Critical
Yderligere oplysninger
This vulnerability exposes hardcoded authentication credentials in public source code repositories, enabling unauthorized access to sensitive system components.
Oplysninger
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-40710 | Dell Container Storage Modules, versions Operator 1.6.0 through 1.16.3 and Helm Charts 1.11.0 through 1.16.3, contain a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. This vulnerability is considered critical as it exposes default authentication credentials in public source code, enabling unauthorized access to sensitive system components. Attackers can leverage these credentials to compromise authentication sessions, exfiltrate cached data, and potentially pivot to additional services within the infrastructure. The public nature of the exposure means any attacker can immediately obtain and use these credentials without requiring any additional privileges or complex attack techniques. | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-40710 | Dell Container Storage Modules, versions Operator 1.6.0 through 1.16.3 and Helm Charts 1.11.0 through 1.16.3, contain a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. This vulnerability is considered critical as it exposes default authentication credentials in public source code, enabling unauthorized access to sensitive system components. Attackers can leverage these credentials to compromise authentication sessions, exfiltrate cached data, and potentially pivot to additional services within the infrastructure. The public nature of the exposure means any attacker can immediately obtain and use these credentials without requiring any additional privileges or complex attack techniques. | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Berørte produkter og udbedring
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| Dell Container Storage Modules | CSM Operator | Versions 1.6.0 through 1.16.3 | Version 1.17.0 or later | Contact Customer Support |
| Dell Container Storage Modules | CSM Helm Charts | Versions 1.11.0 through 1.16.3 | Version 1.17.0 or later | Contact Customer Support |
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| Dell Container Storage Modules | CSM Operator | Versions 1.6.0 through 1.16.3 | Version 1.17.0 or later | Contact Customer Support |
| Dell Container Storage Modules | CSM Helm Charts | Versions 1.11.0 through 1.16.3 | Version 1.17.0 or later | Contact Customer Support |
Revisionshistorik
| Revision | Date | Description |
| 1.0 | 2026-05-21 | Initial Release |
Relaterede oplysninger
Ansvarsfraskrivelse
Berørte produkter
Container Storage Modules Family, Container Storage ModulesArtikelegenskaber
Artikelnummer: 000467149
Artikeltype: Dell Security Advisory
Senest ændret: 21 maj 2026
Find svar på dine spørgsmål fra andre Dell-brugere
Supportservices
Kontrollér, om din enhed er dækket af supportservices.