DSA-2026-220: Security Update for Dell Product Vulnerability

Sommaire: Remediation is available for a vulnerability that could be exploited by malicious users to compromise the affected systems.

Cet article s’applique à Cet article ne s’applique pas à Cet article n’est lié à aucun produit spécifique. Toutes les versions de produits ne sont pas identifiées dans cet article.

Impact

High

Détails

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-32657 Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-32657 Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies recommande à tous ses clients de tenir compte à la fois du score de base CVSS et de tous les scores temporels et environnementaux pertinents qui pourraient avoir une incidence sur la gravité potentielle associée à une vulnérabilité de sécurité particulière.

Produits touchés et correction

CVEs Addressed Product Affected Versions Remediated Version Link
CVE-2026-32657 Dell AppSync Versions prior to 4.6.0.4 Version 4.6.0.4 or later https://dl.dell.com/downloads/JD3VM_AppSync-4.6.0.4-(Build-number-4.6.0.4-74)-Software.zip
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-emc-metro-node/drivers
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-mn-216/drivers
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-emc-mn-215/drivers
CVE-2026-32657 Dell UCC Edge Versions prior to 3.0.2 Version 3.0.2 or later https://www.dell.com/support/product-details/product/ucc-edge/drivers
CVE-2026-32657 Dell VxRail Versions prior to 8.0.330 Version 8.0.330 or later https://www.dell.com/support/product-details/product/vxrail-appliance-series/drivers
CVE-2026-32657 Dell PowerMax Versions prior to 10.3.1.0 Patch 11248 Version 10.3.1.0 Patch 11248 or later Contact customer support and request DSA-2026-153 Requests accepted: 04/13/2026
CVE-2026-32657 Dell Unity Versions prior to 5.5.2 Version 5.5.2 or later https://www.dell.com/support/product-details/product/unity-all-flash-family/drivers
CVE-2026-32657 Dell PowerFlex Manager Versions prior to 4.5.5 Version 4.5.5 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Intelligent Catalog Versions prior to 48.383.00 Version 48.383.00 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Intelligent Catalog Versions prior to 48.378.00 Version 48.378.00 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Rack Versions prior to 4.5.5 Version 4.5.5 or later https://cicodeportal.dell.com/#/home

 

CVEs Addressed Product Affected Versions Remediated Version Link
CVE-2026-32657 Dell AppSync Versions prior to 4.6.0.4 Version 4.6.0.4 or later https://dl.dell.com/downloads/JD3VM_AppSync-4.6.0.4-(Build-number-4.6.0.4-74)-Software.zip
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-emc-metro-node/drivers
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-mn-216/drivers
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-emc-mn-215/drivers
CVE-2026-32657 Dell UCC Edge Versions prior to 3.0.2 Version 3.0.2 or later https://www.dell.com/support/product-details/product/ucc-edge/drivers
CVE-2026-32657 Dell VxRail Versions prior to 8.0.330 Version 8.0.330 or later https://www.dell.com/support/product-details/product/vxrail-appliance-series/drivers
CVE-2026-32657 Dell PowerMax Versions prior to 10.3.1.0 Patch 11248 Version 10.3.1.0 Patch 11248 or later Contact customer support and request DSA-2026-153 Requests accepted: 04/13/2026
CVE-2026-32657 Dell Unity Versions prior to 5.5.2 Version 5.5.2 or later https://www.dell.com/support/product-details/product/unity-all-flash-family/drivers
CVE-2026-32657 Dell PowerFlex Manager Versions prior to 4.5.5 Version 4.5.5 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Intelligent Catalog Versions prior to 48.383.00 Version 48.383.00 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Intelligent Catalog Versions prior to 48.378.00 Version 48.378.00 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Rack Versions prior to 4.5.5 Version 4.5.5 or later https://cicodeportal.dell.com/#/home

 

Historique de révision

RevisionDateDescription
1.02026-08-10Initial Release

 

Reconnaissances

CVE-2026-32657: Dell would like to thank Ouallaout Noureddine for reporting this issue 

Renseignements connexes

Produits touchés

metro node, Dell EMC Unity, AppSync, metro node mn-114, Dell EMC Unity Family |Dell EMC Unity All Flash, Dell EMC Unity Hybrid, Dell Unity Operating Environment (OE)

Produits

PowerFlex rack, VxRail, PowerFlex Appliance, PowerMax, ScaleIO, metro node mn-215, metro node mn-216, PowerFlex rack HW, PowerMax, PowerMaxOS 10, PowerFlex Software, UCC Edge, VxRail 460 and 470 Nodes, VxRail Appliance Series, VxRail G Series Nodes , VxRail D560, VxRail D560F, VxRail E Series Nodes, VxRail E460, VxRail E560, VxRail E560 VCF, VxRail E560F, VxRail E560F VCF, VxRail E560N, VxRail E560N VCF, VxRail E660, VxRail E660F, VxRail E660N, VxRail E665, VxRail E665F, VxRail E665N, VxRail P Series Nodes, VxRail S Series Nodes, VxRail Software, VxRail V Series Nodes, VxRail VD Series Nodes, VxRail VE-660, VxRail VE-6615, VxRail VE-670 ...
Propriétés de l’article
Numéro d’article: 000497857
Type d’article: Dell Security Advisory
Dernière modification: 10 août 2026
Obtenez des réponses à vos questions auprès d’autre utilisateurs de Dell
Services de soutien
Vérifiez si votre appareil est couvert par les services de soutien.