CVE-2026-67270
Received Received - Intake

Improper Certificate Validation in Dell CSM Proxy-Server

Vulnerability report for CVE-2026-67270, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Dell

Description

Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Dell Container Storage Modules (CSM) 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Dell Container Storage Modules (CSM) before version 1.18.0 has an Improper Certificate Validation flaw in its proxy-server component. This allows an unauthenticated attacker on the same network to exploit the issue and potentially access storage backend administrator credentials, leading to information exposure.

Detection Guidance

Detecting this vulnerability requires checking the version of Dell Container Storage Modules (CSM) installed on your system. If the version is prior to 1.18.0, the system is vulnerable. Use commands like 'csm version' or check package managers such as 'rpm -qa | grep dell-csm' or 'dpkg -l | grep dell-csm' to verify the installed version.

Impact Analysis

An attacker could gain access to sensitive storage backend administrator credentials, potentially leading to unauthorized access to storage systems, data breaches, or further network compromise within the affected environment.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage due to potential data exposure.

Mitigation Strategies

Upgrade Dell Container Storage Modules (CSM) to version 1.18.0 or later to address the improper certificate validation vulnerability. Ensure the proxy-server component is updated to prevent unauthorized access to storage backend administrator credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67270. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart