VYPR

Vendor CVEs

Dell

All CVEs

1,740 total · sorted by risk
  • CVE-2024-22452HigMar 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Dell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low privilege user could potentially exploit this vulnerability by modifying files in the installation folder to execute arbitrary code, leading to privilege…

  • CVE-2024-22426HigFeb 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary operating system commands, which will get executed in the context…

  • CVE-2023-39244HigFeb 15, 2024
    risk 0.47cvss 7.3epss 0.01

    DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level…

  • CVE-2023-25535HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.00

    Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can result in local privilege escalation (LPE). This vulnerability only affects first-time installations done prior to 8th March 2023…

  • CVE-2024-22445HigFeb 13, 2024
    risk 0.47cvss 7.2epss 0.01

    Dell PowerProtect Data Manager, version 19.15 and prior versions, contain an OS command injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS,…

  • CVE-2023-32451HigFeb 6, 2024
    risk 0.47cvss 7.3epss 0.00

    Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation and uninstallation

  • CVE-2023-43088HigDec 22, 2023
    risk 0.47cvss 7.2epss 0.00

    Dell Client BIOS contains a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.

  • CVE-2023-48670HigDec 22, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell SupportAssist for Home PCs version 3.14.1 and prior versions contain a privilege escalation vulnerability in the installer. A local low privileged authenticated attacker may potentially exploit this vulnerability, leading to the execution of arbitrary executable on the…

  • CVE-2023-48667HigDec 14, 2023
    risk 0.47cvss 7.2epss 0.02

    Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS…

  • CVE-2023-48665HigDec 14, 2023
    risk 0.47cvss 7.2epss 0.02

    Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.

  • CVE-2023-48664HigDec 14, 2023
    risk 0.47cvss 7.2epss 0.02

    Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.

  • CVE-2023-48663HigDec 14, 2023
    risk 0.47cvss 7.2epss 0.02

    Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.

  • CVE-2023-48662HigDec 14, 2023
    risk 0.47cvss 7.2epss 0.02

    Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.

  • CVE-2023-44291HigDec 4, 2023
    risk 0.47cvss 7.2epss 0.02

    Dell DM5500 5.14.0.0 contains an OS command injection vulnerability in the appliance. A remote attacker with high privileges could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the underlying OS, with the privileges of the…

  • CVE-2023-39257HigDec 2, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder when product installation repair is performed, leading…

  • CVE-2023-39256HigDec 2, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder during product installation and upgrade, leading to…

  • CVE-2023-44290HigNov 23, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell Command | Monitor versions prior to 10.10.0, contain an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability while repairing/changing installation, leading to privilege escalation.

  • CVE-2023-44289HigNov 23, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell Command | Configure versions prior to 4.11.0, contain an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability while repairing/changing installation, leading to privilege escalation.

  • CVE-2023-43086HigNov 23, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell Command | Configure, versions prior to 4.11.0, contains an improper access control vulnerability. A local malicious user could potentially modify files inside installation folder during application upgrade, leading to privilege escalation.

  • CVE-2023-39253HigNov 23, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability, leading to the elevation of privilege on the system.

  • CVE-2023-39259HigNov 16, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability, leading to the elevation of privilege on the system.

  • CVE-2023-43079HigOct 13, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to execute arbitrary code in order to elevate privileges on the…

  • CVE-2023-32458HigSep 27, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerability in Embedded Service Enabler component. A local malicious user could potentially exploit this vulnerability during installation leading to a privilege…

  • CVE-2023-3039HigSep 12, 2023
    risk 0.47cvss 7.3epss 0.00

    SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious user may potentially exploit this vulnerability to perform arbitrary code execution with limited access.

  • CVE-2023-32449HigJun 22, 2023
    risk 0.47cvss 7.2epss 0.00

    Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks

  • CVE-2023-28066HigJun 1, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell OS Recovery Tool, versions 2.2.4013 and 2.3.7012.0, contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability in order to elevate privileges on the system.

  • CVE-2023-28068HigMay 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell Command Monitor, versions 10.9 and prior, contains an improper folder permission vulnerability. A local authenticated malicious user can potentially exploit this vulnerability leading to privilege escalation by writing to a protected directory when Dell Command Monitor is…

  • CVE-2023-28047HigApr 20, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation. A local low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code on the operating system with…

  • CVE-2022-34447HigFeb 11, 2023
    risk 0.47cvss 7.2epss 0.02

    PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains OS Command Injection vulnerability. An authenticated remote attacker with administrative privileges could potentially exploit the issue and execute commands on the system as the root user.

  • CVE-2022-34405HigJan 26, 2023
    risk 0.47cvss 7.3epss 0.00

    An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the application and attach to the process to elevate privileges on the…

  • CVE-2022-34457HigJan 18, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside…

  • CVE-2022-34432HigOct 11, 2022
    risk 0.47cvss 7.3epss 0.00

    Dell Hybrid Client below 1.8 version contains a gedit vulnerability. A guest attacker could potentially exploit this vulnerability, allowing deletion of user and some system files and folders.

  • CVE-2022-34373HigAug 31, 2022
    risk 0.47cvss 7.3epss 0.00

    Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability in order to perform an arbitrary write as system.

  • CVE-2022-23155HigApr 1, 2022
    risk 0.47cvss 7.2epss 0.01

    Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can exploit this vulnerability in order to execute arbitrary code on the system.

  • CVE-2021-36347HigJan 25, 2022
    risk 0.47cvss 7.2epss 0.02

    iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability. An authenticated remote attacker with high privileges could potentially exploit this vulnerability to control process execution and gain access to the…

  • CVE-2021-36296HigJan 25, 2022
    risk 0.47cvss 7.2epss 0.03

    Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

  • CVE-2021-36295HigJan 25, 2022
    risk 0.47cvss 7.2epss 0.03

    Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

  • CVE-2021-21597HigAug 10, 2021
    risk 0.47cvss 7.2epss 0.00

    Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical access to the system could exploit this vulnerability to read sensitive information written to the log files.

  • CVE-2021-21553HigAug 3, 2021
    risk 0.47cvss 7.3epss 0.00

    Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow the CompAdmin user to elevate privileges and break out of Compliance mode. This is a critical vulnerability and Dell recommends upgrading…

  • CVE-2021-21574HigJun 24, 2021
    risk 0.47cvss 7.2epss 0.00

    Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

  • CVE-2021-21573HigJun 24, 2021
    risk 0.47cvss 7.2epss 0.00

    Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

  • CVE-2021-21572HigJun 24, 2021
    risk 0.47cvss 7.2epss 0.00

    Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

  • CVE-2021-21517HigMar 1, 2021
    risk 0.47cvss 7.2epss 0.01

    SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read…

  • CVE-2020-5343HigMay 4, 2020
    risk 0.47cvss 7.3epss 0.00

    Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vulnerability. A local authenticated malicious user with low privileges could exploit this vulnerability to gain unauthorized access…

  • CVE-2020-5332HigMay 4, 2020
    risk 0.47cvss 7.2epss 0.02

    RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privileges could potentially exploit this vulnerability to execute arbitrary commands on the system where the vulnerable application is…

  • CVE-2019-18582HigMar 18, 2020
    risk 0.47cvss 7.2epss 0.05

    Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may…

  • CVE-2019-18581HigMar 18, 2020
    risk 0.47cvss 7.2epss 0.04

    Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may…

  • CVE-2019-3745HigOct 7, 2019
    risk 0.47cvss 7.3epss 0.00

    The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the installation of the product by an administrator. A local…

  • CVE-2019-3736HigSep 27, 2019
    risk 0.47cvss 7.2epss 0.01

    Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the…

  • CVE-2018-1239HigMay 8, 2018
    risk 0.47cvss 7.2epss 0.03

    Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injection vulnerabilities. A remote application admin user could potentially exploit the vulnerabilities to execute arbitrary OS commands as system root on the system…

Page 15 of 35