Dell Container Storage Modules (CSM) Operator 在 1.18.0 版本之前存在一个权限管理不当(Improper Privilege Management)漏洞,该漏洞位于 ContainerStorageModule 自定义资源(CR)的协调器(reconciler)中。低权限的远程攻击者可能利用此漏洞实现权限提升,从而在集群节点上获得 root 级别的访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Dell | Container Storage Modules (CSM) | 0 ~ 1.18.0 or later | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63692 | 10.0 CRITICAL | Dell Container Storage Modules <1.18.0 缺少身份验证致权限提升 |
| CVE-2026-63688 | 10.0 CRITICAL | Dell CSM <v1.18.0 关键函数缺失认证漏洞 |
| CVE-2026-61421 | 9.8 CRITICAL | Dell CSM<1.18.0 硬编码凭证致提权 |
| CVE-2026-54472 | 9.8 CRITICAL | Dell Container Storage Modules <1.18.0 硬编码凭据致信息泄露 |
No comments yet