T
Threats
Dell PowerStore 500T Multiple Vulnerabilities
Overview
CVE: CVE-2026-67271, CVE-2026-67262, CVE-2026-70415
Severity: Critical
Dell has published DSA-2026-330 for three vulnerabilities in Dell PowerStore T. The highest-rated issue, CVE-2026-67271, has a CVSS score of 9.8 and can be exploited remotely without authentication or user interaction.
Affected Versions
Dell PowerStore 500T - PowerStore T OS
Affected: Versions prior to 5.0.0.2-2761110
Fixed: Version 5.0.0.2-2761110 or later
Not affected: Version 5.0.0.2-2761110 or later
Release details: Dell PowerStoreOS 5.0.0.x patch release notes
Dell lists the same affected and remediated versions for PowerStore 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 5200Q, 5200T, 7000T, 9000T and 9200T.
Vulnerability Breakdown
CVE-2026-67271 - SMB/CIFS out-of-bounds write
Severity: Critical
CVSS: 9.8
Description: Dell PowerStore SDNAS contains an out-of-bounds write vulnerability in SMB/CIFS. A remote attacker can send a specially crafted SMB packet to exploit the issue without authentication.
Impact: Denial of service, including a persistent crash when automatic restarts are enabled, and potential remote code execution.
Conditions: Network access to the affected SMB/CIFS service. No privileges or user interaction are required.
CVE-2026-67262 - Missing authorisation
Severity: High
CVSS: 8.8
Description: Dell PowerStore contains a missing authorisation vulnerability. An attacker with access to a mapped host could bypass per-initiator LUN access controls.
Impact: Unauthorised reading from or writing to LUNs that the host is not authorised to access.
Conditions: The attacker must have access to a mapped host. Dell rates attack complexity as high.
CVE-2026-70415 - NFS/RPC unchecked buffer copy
Severity: High
CVSS: 8.1
Description: Dell PowerStore SDNAS contains a buffer copy vulnerability in NFS/RPC that does not check the size of input. An unauthenticated remote attacker could exploit the issue.
Impact: Command execution and denial of service.
Conditions: Remote access to the affected NFS/RPC service. No privileges or user interaction are required, but Dell rates attack complexity as high.
Mitigation
Upgrade PowerStore 500T to PowerStore T OS 5.0.0.2-2761110 or later.
Review the Dell PowerStoreOS supported upgrade paths before upgrading. Some older versions require intermediate upgrades.
If automatic download is disabled, obtain the
PowerStore T OS Upgrade 5.0.0.2-2761110package from Dell PowerStore 500T Drivers and Downloads.Customers using PowerStore as external storage for Nutanix Cloud Platform must install build 2761356 hotfix after upgrading to build 2761110, as directed in the PowerStoreOS 5.0.0.x patch release notes.
Dell has not published a workaround for these vulnerabilities. Applying the remediated release is the required action.
Summary for IT Teams
Products: Dell PowerStore 500T running PowerStore T OS
Threat Level: Critical, CVSS 9.8
Action Required: Identify PowerStore 500T systems running versions earlier than 5.0.0.2-2761110, confirm the supported upgrade path, and upgrade to 5.0.0.2-2761110 or later as a priority.
Reference
Need Help?
Please contact Secure ISS on 1300 769 460. We are here to help you assess exposure, plan the upgrade and strengthen your cybersecurity posture.

