T

Threats

Dell PowerStore 500T Multiple Vulnerabilities

Overview

CVE: CVE-2026-67271, CVE-2026-67262, CVE-2026-70415

Severity: Critical

Dell has published DSA-2026-330 for three vulnerabilities in Dell PowerStore T. The highest-rated issue, CVE-2026-67271, has a CVSS score of 9.8 and can be exploited remotely without authentication or user interaction.


Affected Versions

Dell PowerStore 500T - PowerStore T OS

Dell lists the same affected and remediated versions for PowerStore 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 5200Q, 5200T, 7000T, 9000T and 9200T.


Vulnerability Breakdown

CVE-2026-67271 - SMB/CIFS out-of-bounds write

Severity: Critical

CVSS: 9.8

Description: Dell PowerStore SDNAS contains an out-of-bounds write vulnerability in SMB/CIFS. A remote attacker can send a specially crafted SMB packet to exploit the issue without authentication.

Impact: Denial of service, including a persistent crash when automatic restarts are enabled, and potential remote code execution.

Conditions: Network access to the affected SMB/CIFS service. No privileges or user interaction are required.

CVE-2026-67262 - Missing authorisation

Severity: High

CVSS: 8.8

Description: Dell PowerStore contains a missing authorisation vulnerability. An attacker with access to a mapped host could bypass per-initiator LUN access controls.

Impact: Unauthorised reading from or writing to LUNs that the host is not authorised to access.

Conditions: The attacker must have access to a mapped host. Dell rates attack complexity as high.

CVE-2026-70415 - NFS/RPC unchecked buffer copy

Severity: High

CVSS: 8.1

Description: Dell PowerStore SDNAS contains a buffer copy vulnerability in NFS/RPC that does not check the size of input. An unauthenticated remote attacker could exploit the issue.

Impact: Command execution and denial of service.

Conditions: Remote access to the affected NFS/RPC service. No privileges or user interaction are required, but Dell rates attack complexity as high.


Mitigation

Dell has not published a workaround for these vulnerabilities. Applying the remediated release is the required action.


Summary for IT Teams

Products: Dell PowerStore 500T running PowerStore T OS

Threat Level: Critical, CVSS 9.8

Action Required: Identify PowerStore 500T systems running versions earlier than 5.0.0.2-2761110, confirm the supported upgrade path, and upgrade to 5.0.0.2-2761110 or later as a priority.


Reference


Need Help?

Please contact Secure ISS on 1300 769 460. We are here to help you assess exposure, plan the upgrade and strengthen your cybersecurity posture.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.