MEDIUM 4.3

CVE-2026-35162: Dell PowerFlex Manager Access Control Denial of Service

Dell PowerFlex Manager versions before 5.1.0.1 have an access control flaw that allows low-privilege remote users to trigger denial-of-service conditions. While the attacker needs valid credentials, the barrier to exploitation is relatively low, and the impact centers on service availability rather than data compromise.

Source data · NVD / CISA · public domain

CVSS
3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Weaknesses (CWE)
CWE-284
Affected products
1 configuration(s)
Published / Modified
2026-06-17 / 2026-06-25

NVD description (verbatim)

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-35162 is classified as an Improper Access Control vulnerability (CWE-284) in Dell PowerFlex Manager. The flaw exists in versions prior to 5.1.0.1 and permits authenticated but low-privileged remote users to perform actions that exhaust or disable the service. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L) indicates network-adjacent attack complexity, requiring valid credentials but no user interaction, with impact limited to availability. No confidentiality or integrity compromise is indicated.

Business impact

Exploitation of this vulnerability could degrade or interrupt PowerFlex Manager availability, impacting infrastructure monitoring, configuration management, and operational visibility for Dell storage environments. Organizations relying on PowerFlex Manager for cluster administration could face service interruptions, though data stored in the underlying PowerFlex infrastructure itself is not directly at risk from this flaw. Repeated exploitation could necessitate service restarts or failover procedures.

Affected systems

Dell PowerFlex Manager versions prior to 5.1.0.1 are affected. Organizations running older or unpatched instances in their environment should prioritize inventory and patching. The vulnerability requires network access and valid authentication, so it is not exploitable from untrusted networks unless credentials are compromised or mismanagement of network segmentation has occurred.

Exploitability

Exploitation requires valid remote credentials and network access to the PowerFlex Manager interface. While the barrier is not trivial (an attacker cannot exploit this unauthenticated), any user account—even with minimal privilege—can trigger the denial-of-service condition. CVSS indicates low attack complexity, meaning straightforward exploitation once access is obtained. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting limited active exploitation at publication time, but organizations should not rely on this for prioritization.

Remediation

Upgrade Dell PowerFlex Manager to version 5.1.0.1 or later. This is a straightforward remediation; verify the patch availability from Dell's advisory and plan upgrades according to your maintenance windows. For environments unable to patch immediately, enforce strict access controls, limit network exposure of the PowerFlex Manager interface, and monitor for suspicious authentication activity from low-privilege accounts.

Patch guidance

Apply Dell's official patch to upgrade PowerFlex Manager to 5.1.0.1 or newer. Follow Dell's documented upgrade procedures and test in a non-production environment first. Coordinate upgrades with storage infrastructure change windows to minimize operational disruption. Verify successful patching by confirming the running version post-upgrade and monitoring manager logs for stability.

Detection guidance

Monitor PowerFlex Manager logs and system metrics for signs of repeated authentication from low-privilege accounts followed by service availability issues. Watch for unusual or repetitive denial-of-service indicators such as rapid connection attempts, resource exhaustion events, or manager process restarts correlating with authentication patterns. Correlate authentication logs with application performance and availability metrics to identify exploitation attempts.

Why prioritize this

This is a medium-severity vulnerability with straightforward remediation. Prioritization should be tempered by the authentication requirement; however, any environment with overly permissive account policies or legacy credential hygiene issues should treat this as higher priority. Organizations with high availability requirements for PowerFlex Manager infrastructure should prioritize patching to eliminate availability risk.

Risk score, explained

The CVSS 3.1 score of 4.3 reflects the moderate but real impact on availability combined with the requirement for valid credentials. There is no data confidentiality or integrity risk, limiting the overall severity. The network-accessible nature and low attack complexity increase concern relative to other local-only flaws. The fact that this is not yet in active widespread exploitation (per KEV status) provides a brief window for planned remediation without panic.

Frequently asked questions

Does this vulnerability expose PowerFlex data or storage volumes?

No. CVE-2026-35162 impacts the availability of the PowerFlex Manager application itself, not the security or accessibility of the underlying storage infrastructure or data. The vulnerability does not lead to unauthorized data access, exfiltration, or corruption.

Can this be exploited remotely without any credentials?

No. The vulnerability requires valid authentication (low-privilege account). An attacker cannot exploit it from the internet without legitimate or compromised user credentials for the PowerFlex Manager system.

What versions of PowerFlex Manager should I upgrade to?

Upgrade to version 5.1.0.1 or later. Verify the exact release availability and any interim patches from Dell's official security advisory and release notes.

Is there a workaround if I cannot patch immediately?

While no substitute exists for patching, you can reduce risk by restricting network access to the PowerFlex Manager interface, enforcing strong authentication policies, disabling or closely monitoring low-privilege accounts, and maintaining alert-based monitoring of authentication and availability metrics.

This analysis is provided for informational purposes and based on publicly available vulnerability data as of the publication date. CVSS scores and severity ratings reflect the vendor's assessment and industry standards at time of publication. Actual risk in your environment depends on network topology, credential management practices, and operational context. Always verify patch availability and compatibility with your specific PowerFlex Manager deployment and related infrastructure before applying updates. Consult Dell's official security advisories for authoritative guidance. SEC.co makes no warranty regarding the completeness or accuracy of this information and recommends security teams conduct their own assessment. Source: NVD (public-domain), retrieved 2026-07-27. Analysis generated by SEC.co (claude-haiku-4-5).