Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to information disclosure.
History

Thu, 25 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in Dell PowerFlex Manager Enables Low‑Privilege Information Disclosure

Thu, 25 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to information disclosure. Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to information disclosure.

Thu, 18 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in Dell PowerFlex Manager Enables Low‑Privilege Information Disclosure

Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Description Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to information disclosure.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2026-06-17T15:05:31.825Z

Updated: 2026-06-25T13:03:58.190Z

Reserved: 2026-04-01T05:04:41.954Z

Link: CVE-2026-35068

cve-icon Vulnrichment

Updated: 2026-06-17T17:58:24.914Z

cve-icon NVD

No data.

cve-icon Redhat

No data.