Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.
References
Configurations
History
07 Aug 2026, 20:05
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.dell.com/support/kbdoc/en-us/000496035/dsa-2026-335-security-update-for-dell-virtual-storage-integrator-for-vmware-vsphere-client-multiple-vulnerabilities - Vendor Advisory | |
| First Time |
Dell virtual Storage Integrator
Dell |
|
| CPE | cpe:2.3:a:dell:virtual_storage_integrator:*:*:*:*:*:vmware_vsphere:*:* |
06 Aug 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-06 15:16
Updated : 2026-08-07 20:05
NVD link : CVE-2026-54489
Mitre link : CVE-2026-54489
CVE.ORG link : CVE-2026-54489
JSON object : View
Products Affected
dell
- virtual_storage_integrator
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
