DSA-2025-186: Security Update for Dell PowerScale InsightIQ Multiple Vulnerabilities
Summary: Dell PowerScale InsightIQ remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-30475 |
Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges. |
8.1 |
|
|
CVE-2025-30476 |
Dell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. |
5.3 |
|
|
CVE-2025-36602 |
Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper neutralization of special elements used in an OS command ('OS command injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to command execution. |
5.3 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-30475 |
Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges. |
8.1 |
|
|
CVE-2025-30476 |
Dell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. |
5.3 |
|
|
CVE-2025-36602 |
Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper neutralization of special elements used in an OS command ('OS command injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to command execution. |
5.3 |
Affected Products & Remediation
| CVEs Addressed | Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| CVE-2025-30475, CVE-2025-36602 | PowerScale InsightIQ | PowerScale InsightIQ Simple, PowerScale InsightIQ Scale | Versions 5.0 through 5.2 | Version 6.0 or later | PowerScale InsightIQ Downloads Area |
| CVE-2025-30476 | PowerScale InsightIQ | PowerScale InsightIQ Simple | Version 5.2 | Version 6.0 or later | PowerScale InsightIQ Downloads Area |
| CVEs Addressed | Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| CVE-2025-30475, CVE-2025-36602 | PowerScale InsightIQ | PowerScale InsightIQ Simple, PowerScale InsightIQ Scale | Versions 5.0 through 5.2 | Version 6.0 or later | PowerScale InsightIQ Downloads Area |
| CVE-2025-30476 | PowerScale InsightIQ | PowerScale InsightIQ Simple | Version 5.2 | Version 6.0 or later | PowerScale InsightIQ Downloads Area |
Note:
- The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
- We encourage all customers to adopt the Latest Code Version. For more information on installation requirements refer to the PowerScale InsightIQ - Info Hub.
Workarounds & Mitigations
None
Revision History
| Revision | Date | Description |
| 1.0 | 2025-05-13 | Initial Release |
| 2.0 | 2025-07-09 | Revised version to incorporate CVE-2025-36602 |