DSA-2026-234: Security Update for Dell Container Storage Modules Hard-coded Credentials Vulnerability
Summary: Dell Container Storage Modules remediation is available for Dell Container Storage Modules vulnerability that could be exploited by malicious users to compromise the affected system.
Ez a cikk a következő(k)re vonatkozik:
Ez a cikk nem vonatkozik a következő(k)re:
Ez a cikk nem kapcsolódik egyetlen konkrét termékhez sem.
Ez a cikk nem azonosítja az összes termékverziót.
Impact
Critical
További részletek
This vulnerability exposes hardcoded authentication credentials in public source code repositories, enabling unauthorized access to sensitive system components.
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-40710 | Dell Container Storage Modules, versions Operator 1.6.0 through 1.16.3 and Helm Charts 1.11.0 through 1.16.3, contain a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. This vulnerability is considered critical as it exposes default authentication credentials in public source code, enabling unauthorized access to sensitive system components. Attackers can leverage these credentials to compromise authentication sessions, exfiltrate cached data, and potentially pivot to additional services within the infrastructure. The public nature of the exposure means any attacker can immediately obtain and use these credentials without requiring any additional privileges or complex attack techniques. | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-40710 | Dell Container Storage Modules, versions Operator 1.6.0 through 1.16.3 and Helm Charts 1.11.0 through 1.16.3, contain a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. This vulnerability is considered critical as it exposes default authentication credentials in public source code, enabling unauthorized access to sensitive system components. Attackers can leverage these credentials to compromise authentication sessions, exfiltrate cached data, and potentially pivot to additional services within the infrastructure. The public nature of the exposure means any attacker can immediately obtain and use these credentials without requiring any additional privileges or complex attack techniques. | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Érintett termékek és helyreállítás
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| Dell Container Storage Modules | CSM Operator | Versions 1.6.0 through 1.16.3 | Version 1.17.0 or later | Contact Customer Support |
| Dell Container Storage Modules | CSM Helm Charts | Versions 1.11.0 through 1.16.3 | Version 1.17.0 or later | Contact Customer Support |
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| Dell Container Storage Modules | CSM Operator | Versions 1.6.0 through 1.16.3 | Version 1.17.0 or later | Contact Customer Support |
| Dell Container Storage Modules | CSM Helm Charts | Versions 1.11.0 through 1.16.3 | Version 1.17.0 or later | Contact Customer Support |
Revision History
| Revision | Date | Description |
| 1.0 | 2026-05-21 | Initial Release |
Related Information
Jogi nyilatkozat
Érintett termékek
Container Storage Modules Family, Container Storage ModulesTermék tulajdonságai
Article Number: 000467149
Article Type: Dell Security Advisory
Utoljára módosítva: 21 máj. 2026
Választ kaphat kérdéseire más Dell-felhasználóktól
Támogatási szolgáltatások
Ellenőrizze, hogy a készüléke rendelkezik-e támogatási szolgáltatással.