Dell patches 18 critical flaws that could hand attackers the keys to storage and Kubernetes

Summary

Dell has patched 18 critical vulnerabilities affecting its Container Storage Modules (CSM) and System Update (DSU) software. These flaws could allow unauthenticated attackers to gain root access, bypass authentication, and manipulate storage resources, potentially impacting Kubernetes environments.

IFF Assessment

FOE

The discovery and potential exploitation of critical vulnerabilities that grant attackers root access and control over storage infrastructure represent a significant threat to defenders.

Severity

5.9 Medium

Defender Context

Defenders should prioritize patching Dell Container Storage Modules and System Update to versions 1.18.0 and 2.3.0.0 respectively, as these vulnerabilities offer attackers extensive control over critical storage and Kubernetes infrastructure. The absence of workarounds necessitates immediate updates to prevent potential exploitation.

Read Full Story →