VYPR

Vendor CVEs

Dell

All CVEs

1,740 total · sorted by risk
  • CVE-2024-52543MedDec 25, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

  • CVE-2024-28980MedDec 13, 2024
    risk 0.42cvss 6.5epss 0.01

    Dell RecoverPoint for VMs, version(s) 6.0.x contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the SSH. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

  • CVE-2024-38488MedDec 13, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the…

  • CVE-2024-49602MedDec 9, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell PowerScale OneFS Versions 8.2.2.x through 9.8.0.x contain an improper resource unlocking vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2024-48010MedNov 8, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to escalation of privilege on the application.

  • CVE-2024-47481MedOct 25, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2024-28962MedAug 6, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2024-37139MedJun 26, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a Resource Through its Lifetime vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to…

  • CVE-2024-25970MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to loss of integrity.

  • CVE-2024-24908MedMay 8, 2024
    risk 0.42cvss 6.5epss 0.01

    Dell PowerProtect DM5500 version 5.15.0.0 and prior contain an Arbitrary File Delete via Path Traversal vulnerability. A remote attacker with high privileges could potentially exploit this vulnerability to deletion of arbitrary files stored on the server filesystem.

  • CVE-2024-22425MedFeb 16, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to launch a brute force attack or a dictionary attack against the RecoverPoint…

  • CVE-2024-22230MedFeb 12, 2024
    risk 0.42cvss 6.4epss 0.00

    Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could potentially exploit this vulnerability, stealing session information, masquerading as the affected user or carry out any actions that this user could perform, or to…

  • CVE-2023-50430MedDec 9, 2023
    risk 0.42cvss 6.4epss 0.00

    The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling via Linux, and accepts an unauthenticated configuration packet to select the Windows template database, which allows bypass of…

  • CVE-2023-44306MedDec 4, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell DM5500 contains a path traversal vulnerability in the appliance. A remote attacker with high privileges could potentially exploit this vulnerability to overwrite configuration files stored on the server filesystem.

  • CVE-2023-43076MedNov 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker could potentially exploit this vulnerability to cause an out of memory (OOM) condition.

  • CVE-2023-32476MedJul 20, 2023
    risk 0.42cvss 6.4epss 0.00

    Dell Hybrid Client version 2.0 contains a Sensitive Data Exposure vulnerability. An unauthenticated malicious user on the device can access hard coded secrets in javascript files.

  • CVE-2023-28043MedJun 1, 2023
    risk 0.42cvss 6.5epss 0.00

    Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerability to retrieve the plain text.

  • CVE-2023-25942MedApr 4, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this vulnerability in SMB, leading to a potential denial of service.

  • CVE-2022-34404MedFeb 11, 2023
    risk 0.42cvss 6.5epss 0.00

    Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service.

  • CVE-2022-34387MedFeb 11, 2023
    risk 0.42cvss 6.4epss 0.00

    Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and…

  • CVE-2022-34366MedFeb 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.

  • CVE-2022-46679MedFeb 1, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2022-45103MedJan 18, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file…

  • CVE-2022-34431MedOct 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Dell Hybrid Client below 1.8 version contains a guest user profile corruption vulnerability. A WMS privilege attacker could potentially exploit this vulnerability, leading to DHC system not being accessible.

  • CVE-2022-34429MedSep 30, 2022
    risk 0.42cvss 6.5epss 0.00

    Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification.

  • CVE-2022-29089MedSep 28, 2022
    risk 0.42cvss 6.4epss 0.01

    Dell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclosure vulnerability. A remote, unauthenticated attacker could potentially exploit this vulnerability by reverse engineering to retrieve sensitive information and…

  • CVE-2022-34365MedAug 10, 2022
    risk 0.42cvss 6.5epss 0.01

    WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.

  • CVE-2022-33928MedAug 10, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the…

  • CVE-2022-33925MedAug 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attacker could potentially exploit this vulnerability by bypassing access controls in order to download reports containing sensitive information.

  • CVE-2022-33923MedJul 21, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying…

  • CVE-2022-29085MedJun 2, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored in plain text. A local malicious user…

  • CVE-2022-26868MedJun 2, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the…

  • CVE-2021-36293MedApr 8, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges.

  • CVE-2021-36290MedApr 8, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain privileges.

  • CVE-2021-36337MedDec 21, 2021
    risk 0.42cvss 6.5epss 0.00

    Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 which are susceptible to Man-In-The-Middle attacks thereby compromising Confidentiality and Integrity of data.

  • CVE-2021-36329MedNov 30, 2021
    risk 0.42cvss 6.5epss 0.01

    Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information.

  • CVE-2021-36326MedNov 30, 2021
    risk 0.42cvss 6.5epss 0.01

    Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A remote unauthenticated attacker could potentially exploit this vulnerability, leading to a downgrade in the communications between the client and server into…

  • CVE-2021-36305MedNov 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Dell PowerScale OneFS contains an Unsynchronized Access to Shared Data in a Multithreaded Context in SMB CA handling. An authenticated user of SMB on a cluster with CA could potentially exploit this vulnerability, leading to a denial of service over SMB.

  • CVE-2021-21600MedAug 10, 2021
    risk 0.42cvss 6.5epss 0.01

    Dell EMC NetWorker, 19.4 or older, contain an uncontrolled resource consumption flaw in its API service. An authorized API user could potentially exploit this vulnerability via the web and desktop user interfaces, leading to denial of service in the manageability path.

  • CVE-2021-21581MedAug 3, 2021
    risk 0.42cvss 6.5epss 0.01

    Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.

  • CVE-2021-21563MedAug 3, 2021
    risk 0.42cvss 6.5epss 0.01

    Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its auditing component.This can lead to an authenticated user with low-privileges to trigger a denial of service event.

  • CVE-2020-29499MedJul 19, 2021
    risk 0.42cvss 6.4epss 0.00

    Dell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in PowerStore X environment . A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore…

  • CVE-2021-21591MedJul 12, 2021
    risk 0.42cvss 6.4epss 0.00

    Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.

  • CVE-2021-21590MedJul 12, 2021
    risk 0.42cvss 6.4epss 0.00

    Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.

  • CVE-2021-21588MedJul 12, 2021
    risk 0.42cvss 6.5epss 0.00

    Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Presentation Server and…

  • CVE-2021-21547MedApr 30, 2021
    risk 0.42cvss 6.4epss 0.00

    Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerability when the Dell Upgrade Readiness Utility is run on the system. The credentials of the Unisphere Administrator are stored in plain text. A local malicious…

  • CVE-2020-29501MedJan 5, 2021
    risk 0.42cvss 6.4epss 0.00

    Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The…

  • CVE-2020-29489MedJan 5, 2021
    risk 0.42cvss 6.4epss 0.00

    Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in a system file. A local authenticated attacker with…

  • CVE-2020-26199MedJan 5, 2021
    risk 0.42cvss 6.4epss 0.00

    Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in multiple log files. A local authenticated attacker…

  • CVE-2020-5389MedOct 8, 2020
    risk 0.42cvss 6.5epss 0.01

    Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an information disclosure vulnerability. Authenticated low privileged OMIMSCC users may be able to retrieve sensitive information from the logs.

Page 21 of 35