Dell asks admins to patch max severity CSM flaws as soon as possible

Dell Issues Urgent Warning Over Critical Storage Security Flaws Exposing Admin Credentials and Administrative Control

Dell has issued a critical warning over two maximum-severity vulnerabilities in its Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. The flaws, which allow unauthenticated remote attackers to access sensitive information and gain full administrative control, have been patched in the latest version of CSM, but administrators are urged to update as soon as possible.

The affected modules support several of Dell’s primary storage platforms, including PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT. CSM extends the capabilities of standard Container Storage Interface (CSI) drivers for Kubernetes, making it a critical component in many enterprise environments. However, its vulnerabilities expose sensitive data and administrative controls to remote attackers.

The first flaw, tracked as CVE-2026-63688, allows unauthenticated attackers to access storage backend administrator credentials for all registered storage arrays. This can be used to bypass authorization and gain full administrative control over the storage infrastructure. The second vulnerability, present in the authorization proxy and tenant service, also enables threat actors to gain admin privileges by bypassing authentication controls.

Dell warns that this vulnerability is critical because it allows an unauthenticated attacker to gain complete administrative control over the authorization service, potentially enabling unauthorized access to and manipulation of storage resources across all tenants. This is not just a theoretical concern; similar vulnerabilities have been exploited in the wild in recent years. State-sponsored hackers have abused other Dell vulnerabilities in attacks, including the North Korean Lazarus group and suspected Chinese state-backed hacking groups.

Dell has patched four additional critical-severity security issues that can be exploited without privileges to gain root on cluster nodes, administrative access to the CSM Authorization proxy, forge authentication tokens to gain administrative privileges, and bypass Kubernetes access controls for cluster-wide read access to Kubernetes Secrets. The company recommends customers upgrade at the earliest opportunity by updating their container storage modules to version 1.18.0 or later.

The urgency of this warning is not just about patching a vulnerability but also about protecting sensitive data and preventing potential attacks on enterprise environments. As we’ve seen in recent years, state-sponsored hackers have exploited vulnerabilities like these to gain unauthorized access and manipulate systems. It’s essential for administrators to stay vigilant and prioritize updates to prevent such security breaches.

To protect your environment, make sure you’re running the latest version of CSM (version 1.18.0 or later) and follow Dell’s guidance on patching these vulnerabilities. Regularly review your system logs for suspicious activity and consider implementing additional security measures to detect and respond to potential threats. By taking prompt action, you can minimize the risk of a successful attack and maintain the integrity of your enterprise environment.


Source: Bleeping Computer — 2026-10-02