DSA-2026-220: Security Update for Dell Product Vulnerability

Résumé: Remediation is available for a vulnerability that could be exploited by malicious users to compromise the affected systems.

Cet article concerne Cet article ne concerne pas Cet article n’est associé à aucun produit spécifique. Toutes les versions du produit ne sont pas identifiées dans cet article.

Impact

High

Détails

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-32657 Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-32657 Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies recommande à tous les clients de prendre en compte à la fois le score de base CVSS et les scores temporels et environnementaux pertinents qui peuvent avoir un impact sur la gravité potentielle associée à une faille de sécurité donnée.

Produits concernés et mesure corrective

CVEs Addressed Product Affected Versions Remediated Version Link
CVE-2026-32657 Dell AppSync Versions prior to 4.6.0.4 Version 4.6.0.4 or later https://dl.dell.com/downloads/JD3VM_AppSync-4.6.0.4-(Build-number-4.6.0.4-74)-Software.zip
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-emc-metro-node/drivers
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-mn-216/drivers
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-emc-mn-215/drivers
CVE-2026-32657 Dell UCC Edge Versions prior to 3.0.2 Version 3.0.2 or later https://www.dell.com/support/product-details/product/ucc-edge/drivers
CVE-2026-32657 Dell VxRail Versions prior to 8.0.330 Version 8.0.330 or later https://www.dell.com/support/product-details/product/vxrail-appliance-series/drivers
CVE-2026-32657 Dell PowerMax Versions prior to 10.3.1.0 Patch 11248 Version 10.3.1.0 Patch 11248 or later Contact customer support and request DSA-2026-153 Requests accepted: 04/13/2026
CVE-2026-32657 Dell Unity Versions prior to 5.5.2 Version 5.5.2 or later https://www.dell.com/support/product-details/product/unity-all-flash-family/drivers
CVE-2026-32657 Dell PowerFlex Manager Versions prior to 4.5.5 Version 4.5.5 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Intelligent Catalog Versions prior to 48.383.00 Version 48.383.00 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Intelligent Catalog Versions prior to 48.378.00 Version 48.378.00 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Rack Versions prior to 4.5.5 Version 4.5.5 or later https://cicodeportal.dell.com/#/home

 

CVEs Addressed Product Affected Versions Remediated Version Link
CVE-2026-32657 Dell AppSync Versions prior to 4.6.0.4 Version 4.6.0.4 or later https://dl.dell.com/downloads/JD3VM_AppSync-4.6.0.4-(Build-number-4.6.0.4-74)-Software.zip
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-emc-metro-node/drivers
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-mn-216/drivers
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-emc-mn-215/drivers
CVE-2026-32657 Dell UCC Edge Versions prior to 3.0.2 Version 3.0.2 or later https://www.dell.com/support/product-details/product/ucc-edge/drivers
CVE-2026-32657 Dell VxRail Versions prior to 8.0.330 Version 8.0.330 or later https://www.dell.com/support/product-details/product/vxrail-appliance-series/drivers
CVE-2026-32657 Dell PowerMax Versions prior to 10.3.1.0 Patch 11248 Version 10.3.1.0 Patch 11248 or later Contact customer support and request DSA-2026-153 Requests accepted: 04/13/2026
CVE-2026-32657 Dell Unity Versions prior to 5.5.2 Version 5.5.2 or later https://www.dell.com/support/product-details/product/unity-all-flash-family/drivers
CVE-2026-32657 Dell PowerFlex Manager Versions prior to 4.5.5 Version 4.5.5 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Intelligent Catalog Versions prior to 48.383.00 Version 48.383.00 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Intelligent Catalog Versions prior to 48.378.00 Version 48.378.00 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Rack Versions prior to 4.5.5 Version 4.5.5 or later https://cicodeportal.dell.com/#/home

 

Historique des révisions

RevisionDateDescription
1.02026-08-10Initial Release

 

Remerciements

CVE-2026-32657: Dell would like to thank Ouallaout Noureddine for reporting this issue 

Informations connexes

Produits concernés

metro node, Dell EMC Unity, AppSync, metro node mn-114, Dell EMC Unity Family |Dell EMC Unity All Flash, Dell EMC Unity Hybrid, Dell Unity Operating Environment (OE)

Produits

PowerFlex rack, VxRail, PowerFlex Appliance, PowerMax, ScaleIO, metro node mn-215, metro node mn-216, PowerFlex rack HW, PowerMax, PowerMaxOS 10, PowerFlex Software, UCC Edge, VxRail 460 and 470 Nodes, VxRail Appliance Series, VxRail G Series Nodes , VxRail D560, VxRail D560F, VxRail E Series Nodes, VxRail E460, VxRail E560, VxRail E560 VCF, VxRail E560F, VxRail E560F VCF, VxRail E560N, VxRail E560N VCF, VxRail E660, VxRail E660F, VxRail E660N, VxRail E665, VxRail E665F, VxRail E665N, VxRail P Series Nodes, VxRail S Series Nodes, VxRail Software, VxRail V Series Nodes, VxRail VD Series Nodes, VxRail VE-660, VxRail VE-6615, VxRail VE-670 ...
Propriétés de l’article
Numéro d’article: 000497857
Type d’article: Dell Security Advisory
Dernière modification: 10 Aug 2026
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.