CVE-2026-35065

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Information tampering, Remote execution, Script injection, and Unauthorized access.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:powerflex_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerflex_manager:*:*:*:*:*:*:*:*

History

25 Jun 2026, 14:16

Type Values Removed Values Added
Summary (en) Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack in tandem with DNS cache poisoning. (en) Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Information tampering, Remote execution, Script injection, and Unauthorized access.

25 Jun 2026, 13:16

Type Values Removed Values Added
Summary (en) Dell PowerFlex Manager, version(s) [Versions], contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Information tampering, Remote execution, Script injection, and Unauthorized access. (en) Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack in tandem with DNS cache poisoning.

22 Jun 2026, 18:36

Type Values Removed Values Added
First Time Dell powerflex Manager
Dell
References () https://www.dell.com/support/kbdoc/en-us/000477538/dsa-2026-066-security-update-for-powerflex-software-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000477538/dsa-2026-066-security-update-for-powerflex-software-multiple-vulnerabilities - Vendor Advisory
CPE cpe:2.3:a:dell:powerflex_manager:*:*:*:*:*:*:*:*

17 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 15:16

Updated : 2026-06-25 14:16


NVD link : CVE-2026-35065

Mitre link : CVE-2026-35065

CVE.ORG link : CVE-2026-35065


JSON object : View

Products Affected

dell

  • powerflex_manager
CWE
CWE-306

Missing Authentication for Critical Function