VYPR
Unrated severityNVD Advisory· Published Oct 5, 2023· Updated Sep 19, 2024

CVE-2023-43073

CVE-2023-43073

Description

Dell SmartFabric Storage Software v1.4.0 and prior has an improper input validation vulnerability in RADIUS configuration that allows an authenticated remote attacker to gain unauthorized data access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell SmartFabric Storage Software v1.4.0 and prior has an improper input validation vulnerability in RADIUS configuration that allows an authenticated remote attacker to gain unauthorized data access.

Vulnerability

Dell SmartFabric Storage Software versions v1.4.0 and prior (the Debian package for ESXi/KVM and the ESXi and Linux KVM packages) contain an Improper Input Validation vulnerability in the RADIUS configuration functionality [1]. This flaw occurs during the processing of RADIUS configuration inputs, which are not correctly validated before being used. The vulnerable code path is reachable when an attacker has authenticated access to the management interface of the SmartFabric Storage Software VM.

Exploitation

An attacker must first authenticate to the SmartFabric Storage Software management interface. The attacker then sends specially crafted input to the RADIUS configuration endpoint. Due to the improper input validation, the crafted data bypasses expected checks and triggers the vulnerability [1]. No user interaction beyond the authenticated session is required.

Impact

Successful exploitation leads to unauthorized access to data stored or managed by the SmartFabric Storage Software [1]. The confidentiality of the data is compromised, potentially exposing sensitive storage-related information. The privilege level of the attacker remains as authenticated, but the attack allows access beyond normal authorization boundaries.

Mitigation

Dell has released SmartFabric Storage Software version v1.4.1 for Debian, ESXi, and Linux KVM that addresses this vulnerability [1]. Users should upgrade to v1.4.1 or later. No workarounds are documented for versions prior to the fix. The fixed versions and upgrade details are available in Dell Security Advisory DSA-2023-347 [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.