VYPR

Vendor CVEs

Dell

All CVEs

1,740 total · sorted by risk
  • CVE-2023-32489MedAug 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS 8.2x -9.5x contains a privilege escalation vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, to bypass mode protections and gain elevated privileges.  

  • CVE-2023-32486MedAug 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could potentially exploit this vulnerability, leading to escalation of privileges.

  • CVE-2023-32494MedAug 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to elevation of privilege and affect in compliance mode also.

  • CVE-2023-28065MedJun 23, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation.

  • CVE-2023-32480MedJun 23, 2023
    risk 0.44cvss 6.8epss 0.00

    Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution.

  • CVE-2023-28080MedMay 30, 2023
    risk 0.44cvss 6.7epss 0.00

    PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities. A regular user (non-admin) can exploit these issues to potentially escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM.

  • CVE-2023-23693MedMay 23, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility. A local high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's…

  • CVE-2023-28070MedMay 3, 2023
    risk 0.44cvss 6.7epss 0.00

    Alienware Command Center Application, versions 5.5.43.0 and prior, contain an improper access control vulnerability. A local malicious user could potentially exploit this vulnerability during installation or update process leading to privilege escalation.

  • CVE-2023-25940MedApr 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. A high privileged local attacker could potentially exploit this vulnerability, leading to system takeover and it breaks the compliance mode guarantees.

  • CVE-2023-25536MedMar 2, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to a potential system takeover.

  • CVE-2022-46677MedFeb 11, 2023
    risk 0.44cvss 6.8epss 0.01

    Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroup under a group for which the admin is not authorized.

  • CVE-2022-34450MedFeb 11, 2023
    risk 0.44cvss 6.7epss 0.00

    PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability. An authenticated admin user could potentially exploit this issue and gain unrestricted control/code execution on the system as root.

  • CVE-2022-24410MedFeb 10, 2023
    risk 0.44cvss 6.8epss 0.00

    Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces.

  • CVE-2022-34454MedFeb 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user could potentially exploit this vulnerability, leading to system takeover. This impacts compliance mode clusters.

  • CVE-2022-45095MedFeb 1, 2023
    risk 0.44cvss 6.7epss 0.01

    Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of…

  • CVE-2022-34438MedOct 21, 2022
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance mode clusters.

  • CVE-2022-34437MedOct 21, 2022
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious user could potentially exploit this vulnerability, leading to a full system compromise. This impacts compliance mode clusters.

  • CVE-2022-31239MedOct 21, 2022
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability. A privileged local user may potentially exploit this vulnerability, leading to disclosure of this sensitive data.

  • CVE-2022-34434MedOct 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the Postgres database. A threat actor with root level access to either the vApp or containerized versions of Cloud Mobility may potentially exploit this…

  • CVE-2022-34402MedOct 10, 2022
    risk 0.44cvss 6.8epss 0.01

    Dell Wyse ThinOS 2205 contains a Regular Expression Denial of Service Vulnerability in UI. An admin privilege attacker could potentially exploit this vulnerability, leading to denial-of-service.

  • CVE-2022-29083MedAug 9, 2022
    risk 0.44cvss 6.8epss 0.00

    Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.

  • CVE-2020-35164MedJul 11, 2022
    risk 0.44cvss 6.7epss 0.01

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

  • CVE-2020-29506MedJul 11, 2022
    risk 0.44cvss 6.8epss 0.01

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.

  • CVE-2022-26865MedMay 26, 2022
    risk 0.44cvss 6.8epss 0.00

    Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery authentication in order to run arbitrary code on the…

  • CVE-2022-22550MedApr 12, 2022
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading to account take over.

  • CVE-2021-36318MedDec 21, 2021
    risk 0.44cvss 6.7epss 0.00

    Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially exploit this vulnerability, leading to a complete outage.

  • CVE-2021-36317MedDec 21, 2021
    risk 0.44cvss 6.7epss 0.00

    Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials…

  • CVE-2021-36316MedDec 21, 2021
    risk 0.44cvss 6.7epss 0.01

    Dell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability in AUI. A malicious user with high privileges could potentially exploit this vulnerability, leading to the disclosure of the AUI info and performing some…

  • CVE-2021-36315MedNov 12, 2021
    risk 0.44cvss 6.8epss 0.00

    Dell EMC PowerScale Nodes contain a hardware design flaw. This may allow a local unauthenticated user to escalate privileges. This also affects Compliance mode and for Compliance mode clusters, is a critical vulnerability. Dell EMC recommends applying the workaround at your…

  • CVE-2021-21570MedSep 28, 2021
    risk 0.44cvss 6.8epss 0.01

    Dell NetWorker, versions 18.x and 19.x contain an Information disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information.

  • CVE-2021-21569MedSep 28, 2021
    risk 0.44cvss 6.8epss 0.01

    Dell NetWorker, versions 18.x and 19.x contain a Path traversal vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information.

  • CVE-2020-26186MedJan 8, 2021
    risk 0.44cvss 6.8epss 0.00

    Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the RuntimeServices structure to execute arbitrary code in System Management…

  • CVE-2020-26183MedOct 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Dell EMC NetWorker versions prior to 19.3.0.2 contain an improper authorization vulnerability. Certain remote users with low privileges may exploit this vulnerability to perform 'nsrmmdbd' operations in an unintended manner.

  • CVE-2020-26182MedOct 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may exploit this vulnerability to perform 'saveset' related operations in an unintended manner. The vulnerability is not exploitable…

  • CVE-2020-5379MedSep 2, 2020
    risk 0.44cvss 6.8epss 0.00

    Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management…

  • CVE-2020-5378MedSep 2, 2020
    risk 0.44cvss 6.8epss 0.00

    Dell G7 17 7790 BIOS versions prior to 1.13.2 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management…

  • CVE-2020-5376MedSep 2, 2020
    risk 0.44cvss 6.8epss 0.00

    Dell Inspiron 7347 BIOS versions prior to A13 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management…

  • CVE-2020-5385MedAug 18, 2020
    risk 0.44cvss 6.7epss 0.00

    Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malicious user with low privileges could potentially exploit this vulnerability to…

  • CVE-2020-5358MedJun 15, 2020
    risk 0.44cvss 6.7epss 0.00

    Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to incorrect permissions. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated…

  • CVE-2020-5348MedApr 4, 2020
    risk 0.44cvss 6.8epss 0.00

    Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in…

  • CVE-2019-18577MedMar 13, 2020
    risk 0.44cvss 6.7epss 0.00

    Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability. A malicious local user with XtremIO xinstall privileges may exploit this vulnerability to gain root access.

  • CVE-2019-18576MedMar 13, 2020
    risk 0.44cvss 6.7epss 0.00

    Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files. Malicious local users with access to the log files may use the exposed passwords to gain access to XtremIO with the privileges of…

  • CVE-2019-18579MedDec 16, 2019
    risk 0.44cvss 6.8epss 0.00

    Settings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability. The BIOS configuration for the "Enable Thunderbolt (and PCIe behind TBT) pre-boot modules" setting is enabled by default. A local unauthenticated attacker with physical…

  • CVE-2019-3726MedSep 24, 2019
    risk 0.44cvss 6.7epss 0.00

    An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and Framework file versions prior to 103.4.6.69 used in Dell EMC Servers. Dell Update Package (DUP) Framework file versions prior to…

  • CVE-2019-3717MedAug 5, 2019
    risk 0.44cvss 6.8epss 0.00

    Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards…

  • CVE-2018-11077MedNov 26, 2018
    risk 0.44cvss 6.7epss 0.01

    'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin…

  • CVE-2018-1184MedFeb 3, 2018
    risk 0.44cvss 6.7epss 0.01

    An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versions prior to 5.0.1.3. Command injection vulnerability in Boxmgmt CLI may allow a malicious user with boxmgmt privileges to bypass…

  • CVE-2017-4983MedMay 4, 2017
    risk 0.44cvss 6.7epss 0.00

    EMC Data Domain OS 5.2 through 5.7 before 5.7.3.0 and 6.0 before 6.0.1.0 is affected by a privilege escalation vulnerability that may potentially be exploited by attackers to compromise the affected system.

  • CVE-2015-4056MedFeb 21, 2017
    risk 0.44cvss 6.7epss 0.00

    The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which makes it easier for local users to discover credentials by leveraging administrative access.

  • CVE-2016-8216MedFeb 3, 2017
    risk 0.44cvss 6.7epss 0.01

    EMC Data Domain OS (DD OS) 5.4 all versions, EMC Data Domain OS (DD OS) 5.5 family all versions prior to 5.5.5.0, EMC Data Domain OS (DD OS) 5.6 family all versions prior to 5.6.2.0, EMC Data Domain OS (DD OS) 5.7 family all versions prior to 5.7.2.10 has a command injection…

Page 19 of 35