Dell’s Container Storage Modules (CSM) were found to contain multiple critical vulnerabilities that can allow unauthenticated remote attackers to gain full administrative control of affected storage environments. The most severe issues — two CVSS 10.0 flaws — permit attackers to bypass authentication and escalate to administrator privileges, while other high-severity flaws enable privilege escalation inside Kubernetes clusters or token forgery.
