VYPR

Dell Update Package (DUP) Framework

by Dell

CVEs (7)

  • CVE-2026-71180HigSep 16, 2026
    risk 0.53cvss 8.2epss 0.00

    Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2026-23857HigFeb 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of…

  • CVE-2025-22395HigJan 7, 2025
    risk 0.53cvss 8.2epss 0.00

    Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary remote scripts on the server. Exploitation may…

  • CVE-2026-71179HigSep 16, 2026
    risk 0.47cvss 7.3epss 0.01

    Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to…

  • CVE-2026-86358MedSep 16, 2026
    risk 0.42cvss 6.5epss 0.00

    Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.

  • CVE-2026-71182LowSep 16, 2026
    risk 0.20cvss 3.0epss 0.00

    Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for…

  • CVE-2026-71181LowSep 16, 2026
    risk 0.20cvss 3.0epss 0.00

    Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for…