Dell has patched multiple critical flaws in Container Storage Module (CSM), the software that ties Dell storage arrays to Kubernetes, after BleepingComputer and The Hacker News reported bugs that can hand an unauthenticated attacker administrative control. The package includes authentication bypasses, hard-coded credentials, and privilege-escalation flaws, with Dell urging immediate remediation.
The weakness is in the trust path, not just one service. One flaw lets an attacker skip login and pull backend storage administrator credentials; another lets them forge administrative tokens that CSM accepts as valid; a third can push a low-privilege attacker to root on Kubernetes nodes. In other words, the system is treating attacker-supplied material as if it came from a trusted admin channel.
For operators, the exposure sits across the storage control plane that CSM mediates: backend arrays, authorization services, and cluster nodes all inherit the blast radius if that boundary is crossed. Patching removes the defects, but it does not change the fact that CSM was the gatekeeper for storage privileges in the first place.
Dell asks admins to patch max severity CSM flaws as soon as possible
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments.