Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS
Published Aug 18, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.83%
Description
Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service and remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for remote code execution.
Affected products
-
- Version 0StatusaffectedConstraints<5.0.0.2-2761110 or later
- Version
-
- Version 0StatusaffectedConstraints<5.0.0.2-2761110 or later
- Version
-
- Version 0StatusaffectedConstraints<5.0.0.2-2761110 or later
- Version
-
- Version 0StatusaffectedConstraints<5.0.0.2-2761110 or later
- Version
-
- Version 0StatusaffectedConstraints<5.0.0.2-2761110 or later
- Version
-
- Version 0StatusaffectedConstraints<5.0.0.2-2761110 or later
- Version
-
- Version 0StatusaffectedConstraints<5.0.0.2-2761110 or later
- Version
-
- Version 0StatusaffectedConstraints<5.0.0.2-2761110 or later
- Version
-
- Version 0StatusaffectedConstraints<5.0.0.2-2761110 or later
- Version
-
- Version 0StatusaffectedConstraints<5.0.0.2-2761110 or later
- Version
-
- Version 0StatusaffectedConstraints<5.0.0.2-2761110 or later
- Version
-
- Version 0StatusaffectedConstraints<5.0.0.2-2761110 or later
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Dell | PowerStore 1000T | unaffected |
| ||||||
| Dell | PowerStore 1200T | unaffected |
| ||||||
| Dell | PowerStore 3000T | unaffected |
| ||||||
| Dell | PowerStore 3200Q | unaffected |
| ||||||
| Dell | PowerStore 3200T | unaffected |
| ||||||
| Dell | PowerStore 5000T | unaffected |
| ||||||
| Dell | PowerStore 500T | unaffected |
| ||||||
| Dell | PowerStore 5200Q | unaffected |
| ||||||
| Dell | PowerStore 5200T | unaffected |
| ||||||
| Dell | PowerStore 7000T | unaffected |
| ||||||
| Dell | PowerStore 9000T | unaffected |
| ||||||
| Dell | PowerStore 9200T | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
Change history (0)
No recorded changes yet.