VYPR

CloudLink

by Dell

CVEs (21)

  • CVE-2022-34379CriSep 1, 2022
    risk 0.61cvss 9.4epss 0.01

    Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active directory usernames, could potentially exploit this vulnerability to gain unauthorized access to the system.

  • CVE-2022-34380CriSep 1, 2022
    risk 0.60cvss 9.3epss 0.00

    Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink system console.…

  • CVE-2021-36313CriNov 23, 2021
    risk 0.59cvss 9.1epss 0.02

    Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges…

  • CVE-2021-36312CriNov 23, 2021
    risk 0.59cvss 9.1epss 0.01

    Dell EMC CloudLink 7.1 and all prior versions contain a Hard-coded Password Vulnerability. A remote high privileged attacker, with the knowledge of the hard-coded credentials, may potentially exploit this vulnerability to gain unauthorized access to the system.

  • CVE-2022-24414HigMay 26, 2022
    risk 0.49cvss 7.6epss 0.01

    Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests. These request parameters can get logged in reverse proxies and server logs. Attackers may potentially use these tokens to access CloudLink server. Tokens should not be used in request URL…

  • CVE-2021-36314HigNov 23, 2021
    risk 0.46cvss 7.1epss 0.01

    Dell EMC CloudLink 7.1 and all prior versions contain an Arbitrary File Creation Vulnerability. A remote unauthenticated attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary files on the end user system.

  • CVE-2024-38482MedAug 2, 2024
    risk 0.43cvss 6.6epss 0.00

    CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privileged malicious user with remote access could potentially exploit this vulnerability, leading to execute unauthorized actions and…

  • CVE-2023-28076MedMay 16, 2023
    risk 0.38cvss 5.9epss 0.00

    CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability leading to some information disclosure.

  • CVE-2021-36334MedNov 23, 2021
    risk 0.38cvss 5.9epss 0.01

    Dell EMC CloudLink 7.1 and all prior versions contain a CSV formula Injection Vulnerability. A remote high privileged attacker, may potentially exploit this vulnerability, leading to arbitrary code execution on end user machine

  • CVE-2021-36333MedNov 23, 2021
    risk 0.36cvss 5.5epss 0.00

    Dell EMC CloudLink 7.1 and all prior versions contain a Buffer Overflow Vulnerability. A local low privileged attacker, may potentially exploit this vulnerability, leading to an application crash.

  • CVE-2021-36332MedNov 23, 2021
    risk 0.35cvss 5.4epss 0.01

    Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privileged attacker, may potentially exploit this vulnerability, directing end user to arbitrary and potentially malicious websites.

  • CVE-2021-36335MedNov 23, 2021
    risk 0.28cvss 4.3epss 0.01

    Dell EMC CloudLink 7.1 and all prior versions contain an Improper Input Validation Vulnerability. A remote low privileged attacker, may potentially exploit this vulnerability, leading to execution of arbitrary files on the server

  • CVE-2024-37137LowJun 28, 2024
    risk 0.25cvss 3.8epss 0.00

    Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to privileged information disclosure.

  • CVE-2025-46366Nov 5, 2025
    risk 0.00cvss epss 0.00

    Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation or access to the database to obtain confidential information.

  • CVE-2025-46424Nov 5, 2025
    risk 0.00cvss epss 0.00

    Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerability. A high privileged attacker could potentially exploit this vulnerability leading to Denial of service.

  • CVE-2025-46365Nov 5, 2025
    risk 0.00cvss epss 0.00

    Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command Injection on an affected Dell CloudLink.

  • CVE-2025-46364Nov 5, 2025
    risk 0.00cvss epss 0.00

    Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain control of system.

  • CVE-2025-45379Nov 5, 2025
    risk 0.00cvss epss 0.01

    Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell access of system.

  • CVE-2025-30479Nov 5, 2025
    risk 0.00cvss epss 0.01

    Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control of system.

  • CVE-2025-45378Nov 5, 2025
    risk 0.00cvss epss 0.00

    Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and gain access of shell and escalate privilege, gain unauthorized access of system. If ssh is enabled…

Page 1 of 2