DSA-2026-220: Security Update for Multiple Dell Products Symbolic Link Following Vulnerability

Resumo: Remediation is available for a vulnerability that could be exploited by malicious users to compromise the affected systems.

Este artigo aplica-se a Este artigo não se aplica a Este artigo não está vinculado a nenhum produto específico. Nem todas as versões do produto estão identificadas neste artigo.

Impacto

High

Dados

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-32657 Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-32657 Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

 

A Dell Technologies recomenda que todos os clientes levem em consideração a pontuação base CVSS e as pontuações temporais e ambientais pertinentes que possam afetar a gravidade potencial associada a uma vulnerabilidade de segurança específica.

Produtos afetados e soluções

CVEs Addressed Product Affected Versions Remediated Version Link
CVE-2026-32657 Dell AppSync Versions prior to 4.6.0.4 Version 4.6.0.4 or later https://dl.dell.com/downloads/JD3VM_AppSync-4.6.0.4-(Build-number-4.6.0.4-74)-Software.zip
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-emc-metro-node/drivers
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-mn-216/drivers
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-emc-mn-215/drivers
CVE-2026-32657 Dell UCC Edge Versions prior to 3.0.2 Version 3.0.2 or later https://www.dell.com/support/product-details/product/ucc-edge/drivers
CVE-2026-32657 Dell VxRail Versions prior to 8.0.330 Version 8.0.330 or later https://www.dell.com/support/product-details/product/vxrail-appliance-series/drivers
CVE-2026-32657 Dell PowerMax Versions prior to 10.3.1.0 Patch 11248 Version 10.3.1.0 Patch 11248 or later Contact customer support and request DSA-2026-153 Requests accepted: 04/13/2026
CVE-2026-32657 Dell Unity Versions prior to 5.5.2 Version 5.5.2 or later https://www.dell.com/support/product-details/product/unity-all-flash-family/drivers
CVE-2026-32657 Dell PowerFlex Manager Versions prior to 4.5.5 Version 4.5.5 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Intelligent Catalog Versions prior to 48.383.00 Version 48.383.00 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Intelligent Catalog Versions prior to 48.378.00 Version 48.378.00 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Rack Versions prior to 4.5.5 Version 4.5.5 or later https://cicodeportal.dell.com/#/home

 

CVEs Addressed Product Affected Versions Remediated Version Link
CVE-2026-32657 Dell AppSync Versions prior to 4.6.0.4 Version 4.6.0.4 or later https://dl.dell.com/downloads/JD3VM_AppSync-4.6.0.4-(Build-number-4.6.0.4-74)-Software.zip
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-emc-metro-node/drivers
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-mn-216/drivers
CVE-2026-32657 Dell Metro Node Versions prior to 9.1.0.0 Version 9.1.0.0 or later https://www.dell.com/support/product-details/product/dell-emc-mn-215/drivers
CVE-2026-32657 Dell UCC Edge Versions prior to 3.0.2 Version 3.0.2 or later https://www.dell.com/support/product-details/product/ucc-edge/drivers
CVE-2026-32657 Dell VxRail Versions prior to 8.0.330 Version 8.0.330 or later https://www.dell.com/support/product-details/product/vxrail-appliance-series/drivers
CVE-2026-32657 Dell PowerMax Versions prior to 10.3.1.0 Patch 11248 Version 10.3.1.0 Patch 11248 or later Contact customer support and request DSA-2026-153 Requests accepted: 04/13/2026
CVE-2026-32657 Dell Unity Versions prior to 5.5.2 Version 5.5.2 or later https://www.dell.com/support/product-details/product/unity-all-flash-family/drivers
CVE-2026-32657 Dell PowerFlex Manager Versions prior to 4.5.5 Version 4.5.5 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Intelligent Catalog Versions prior to 48.383.00 Version 48.383.00 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Intelligent Catalog Versions prior to 48.378.00 Version 48.378.00 or later https://cicodeportal.dell.com/#/home
CVE-2026-32657 Dell PowerFlex Rack Versions prior to 4.5.5 Version 4.5.5 or later https://cicodeportal.dell.com/#/home

 

Histórico de revisão

RevisionDateDescription
1.02026-08-10Initial Release
2.02026-08-11Updated title for clarity
3.02026-08-14Updated the Categories section

 

Agradecimentos

CVE-2026-32657: Dell would like to thank Ouallaout Noureddine for reporting this issue 

Informações relacionadas

Produtos afetados

metro node, Dell EMC Unity, AppSync, metro node mn-114, Dell EMC Unity Family |Dell EMC Unity All Flash, Dell EMC Unity Hybrid, Dell Unity Operating Environment (OE)

Produtos

PowerFlex rack, VxRail, PowerFlex Appliance, PowerMax, ScaleIO, metro node mn-215, metro node mn-216, PowerFlex rack HW, PowerMax, PowerMaxOS 10, PowerFlex Software, UCC Edge, VxRail 460 and 470 Nodes, VxRail Appliance Series, VxRail G Series Nodes , VxRail D560, VxRail D560F, VxRail E Series Nodes, VxRail E460, VxRail E560, VxRail E560 VCF, VxRail E560F, VxRail E560F VCF, VxRail E560N, VxRail E560N VCF, VxRail E660, VxRail E660F, VxRail E660N, VxRail E665, VxRail E665F, VxRail E665N, VxRail P Series Nodes, VxRail S Series Nodes, VxRail Software, VxRail V Series Nodes, VxRail VD Series Nodes, VxRail VE-660, VxRail VE-6615, VxRail VE-670 ...
Propriedades do artigo
Número do artigo: 000497857
Tipo de artigo: Dell Security Advisory
Último modificado: 14 ago. 2026
Encontre as respostas de outros usuários da Dell para suas perguntas.
Serviços de suporte
Verifique se o dispositivo está coberto pelos serviços de suporte.