Cyber Resilience

CVE-2026-40641

Crypto Weakness in Dell Powerflex Manager ≤ 4.5.5.2

Published
17 June 2026
Modified
25 June 2026
Patch / advisory
CVSS Score v3.1 4.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score 0.0010 1th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2026-40641 is a medium-severity Use of a Broken or Risky Cryptographic Algorithm (CWE-327) vulnerability in Dell Powerflex Manager. Its CVSS base score is 4.8 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to SC-13 (Cryptographic Protection) and SI-2 (Flaw Remediation) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

Remote unauthenticated exploitation of broken crypto in public-facing Dell PowerFlex Manager enables initial access via public app exploitation.

Confidence: MEDIUM · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2026-49502Same product: Dell Powerflex Manager
CVE-2026-32804Same product: Dell Powerflex Manager
CVE-2026-35069Same product: Dell Powerflex Manager
CVE-2026-35066Same product: Dell Powerflex Manager
CVE-2026-56689Same product: Dell Powerflex Manager
CVE-2026-35065Same product: Dell Powerflex Manager
CVE-2026-56690Same product: Dell Powerflex Manager
CVE-2026-56688Same product: Dell Powerflex Manager
CVE-2026-35067Same product: Dell Powerflex Manager
CVE-2025-36599Same product: Dell Powerflex Manager

Affected Assets

dell
powerflex manager
≤ 4.5.5.2 · 4.6.0 — 5.1.0.1

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • SC-13 Cryptographic Protection
  • SI-2 Flaw Remediation
  • SC-8 Transmission Confidentiality and Integrity
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 6 hardening rules · 6 OS baselines
Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly requires use of approved cryptographic algorithms and modules, eliminating the broken algorithm (CWE-327) that enables disclosure/tampering.

prevent

Mandates timely flaw remediation and patching, directly addressing the vulnerable PowerFlex Manager versions prior to 5.1.0.1.

prevent

Requires cryptographic protection of transmitted information to prevent disclosure and tampering over remote connections.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.DS-01 partial match
prevents

PR.DS-01 promotes encryption for data-at-rest but never requires strong algorithms, leaving CWE-327 fully possible; the weakness is also far broader than data-at-rest so one narrow control removes none of its total risk.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

Mandating approved algorithms, cipher strength and usage standards directly stops the selection of broken or weak cryptographic primitives that attackers can exploit.

prevents

The explicit call-out of cryptography-related legal constraints (import/export, key escrow, digital-signature validity) reduces the likelihood that an organization will adopt broken or non-compliant cryptographic algorithms that violate those rules.

prevents

Access to current specialist guidance and early vulnerability alerts enables timely replacement of broken or risky cryptographic algorithms with stronger alternatives.

References