CVE-2026-32657
Summary
| CVE | CVE-2026-32657 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-18 18:17:28 UTC |
| Updated | 2026-08-19 04:16:58 UTC |
| Description | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
Risk And Classification
Primary CVSS: v3.1 7.3 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Problem Types: CWE-61 | CWE-61 CWE-61: UNIX Symbolic Link (Symlink) Following
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.3 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.3 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Dell | AppSync | affected 4.6.0.4 or later semver | Not specified |
| CNA | Dell | Metro Node | affected 4.6.0.4 or later semver | Not specified |
| CNA | Dell | UCC Edge | affected 3.0.2 or later semver | Not specified |
| CNA | Dell | VxRail | affected 8.0.330 or later semver | Not specified |
| CNA | Dell | PowerMax | affected 10.3.1.0 Patch 11248 or later semver | Not specified |
| CNA | Dell | Unity | affected 5.5.2 or later semver | Not specified |
| CNA | Dell | PowerFlex Manager | affected 4.5.5 or later semver | Not specified |
| CNA | Dell | PowerFlex Intelligent Catalog | affected 48.383.00 or later semver | Not specified |
| CNA | Dell | PowerFlex Intelligent Catalog | affected 48.378.00 or later semver | Not specified |
| CNA | Dell | PowerFlex Rack | affected 4.5.5 or later semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.dell.com/support/kbdoc/en-us/000497857/dsa-2026-220-security-update-fo... | [email protected] | www.dell.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.