CVE-2026-54472 — Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs.
Description
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
None
Integrity
A
None
Availability
Affected
- Vendor
- dell
- Product
- container storage modules
Versions
- < 1.18.0
Stated as the source expressed them.
Related threats
same CWE or vendorCVE-2026-84891 — IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to obtain sensitive information due to use of hard-coded credentials.
CVE-2026-84891 · 1h ago
CVE-2026-84250 — IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component.
CVE-2026-84250 · 3h ago
CVE-2026-85488 — Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer.
CVE-2026-85488 · 16h ago
CVE-2026-85422 — A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binar…
CVE-2026-85422 · 16h ago
CVE-2026-92861 — The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the applic…
CVE-2026-92861 · 20h ago
CVE-2026-62252 — Homer is open source telecom observability software.
CVE-2026-62252 · 1d ago