VYPR

Vendor CVEs

Dell

All CVEs

1,740 total · sorted by risk
  • CVE-2024-49558HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2024-49557HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this…

  • CVE-2024-48837HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution

  • CVE-2024-39585HigSep 6, 2024
    risk 0.51cvss 7.9epss 0.00

    Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and…

  • CVE-2024-37127HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and…

  • CVE-2024-28964HigJun 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user.…

  • CVE-2024-0172HigApr 3, 2024
    risk 0.51cvss 7.9epss 0.00

    Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.

  • CVE-2024-25959HigMar 28, 2024
    risk 0.51cvss 7.9epss 0.00

    Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges.

  • CVE-2023-44283HigFeb 14, 2024
    risk 0.51cvss 7.8epss 0.00

    In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respective PCs. This issue may potentially enable privilege…

  • CVE-2024-22228HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root…

  • CVE-2024-22227HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability execute commands with root privileges.

  • CVE-2024-22225HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.

  • CVE-2024-22224HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.

  • CVE-2024-22223HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's…

  • CVE-2024-22222HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the…

  • CVE-2024-0170HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.…

  • CVE-2024-0168HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to inject arbitrary operating system commands. This vulnerability allows an…

  • CVE-2024-0167HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges.

  • CVE-2024-0166HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges.

  • CVE-2024-0165HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.

  • CVE-2024-0164HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary commands with elevated privileges.

  • CVE-2023-25543HigFeb 6, 2024
    risk 0.51cvss 7.8epss 0.00

    Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability in order to elevate privileges on the system.

  • CVE-2024-22432HigJan 25, 2024
    risk 0.51cvss 7.8epss 0.00

    Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit this vulnerability, leading to the…

  • CVE-2023-44285HigDec 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to escalation of privilege.

  • CVE-2023-44277HigDec 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on…

  • CVE-2023-4401HigOct 5, 2023
    risk 0.51cvss 7.8epss 0.01

    Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of the ‘more’ command. A local or remote authenticated attacker could potentially exploit this vulnerability, leading to the ability to gain root-level access.…

  • CVE-2023-43069HigOct 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell SmartFabric Storage Software v1.4 (and earlier) contain(s) an OS Command Injection Vulnerability in the CLI. An authenticated local attacker could potentially exploit this vulnerability, leading to possible injection of parameters to curl or docker.

  • CVE-2023-43068HigOct 5, 2023
    risk 0.51cvss 7.8epss 0.01

    Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the restricted shell in SSH. An authenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands.

  • CVE-2023-32477HigSep 29, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged malicious user may potentially exploit this vulnerability to gain elevated privileges.

  • CVE-2023-28072HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Alienware Command Center, versions prior to 5.5.51.0, contain a deserialization of untrusted data vulnerability. A local malicious user could potentially send specially crafted requests to the .NET Remoting server to run arbitrary code on the system.

  • CVE-2023-39250HigAug 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could…

  • CVE-2023-32495HigAug 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker could potentially exploit this vulnerability, leading to escalation of privileges.

  • CVE-2023-32487HigAug 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service, code execution and information disclosure.

  • CVE-2023-28051HigApr 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit this vulnerability to elevate privileges on the system.

  • CVE-2023-25941HigApr 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to Denial of service, escalation of privileges, and information disclosure. This vulnerability…

  • CVE-2023-24575HigFeb 21, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system

  • CVE-2022-34384HigFeb 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore…

  • CVE-2023-24569HigFeb 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Alienware Command Center versions 5.5.37.0 and prior contain an Improper Input validation vulnerability. A local authenticated malicious user could potentially send malicious input to a named pipe in order to elevate privileges on the system.

  • CVE-2023-22573HigFeb 1, 2023
    risk 0.51cvss 7.9epss 0.00

    Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure.

  • CVE-2023-22572HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privilege local attacker could potentially exploit this vulnerability, leading to system takeover.

  • CVE-2022-45099HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise

  • CVE-2022-34459HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get applicable driver component. A local malicious user could potentially exploit this vulnerability leading to malicious payload…

  • CVE-2022-34443HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Rugged Control Center, versions prior to 4.5, contain an Improper Input Validation in the Service EndPoint. A Local Low Privilege attacker could potentially exploit this vulnerability, leading to an Escalation of privileges.

  • CVE-2022-33920HigOct 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell GeoDrive, versions prior to 2.2, contains an Unquoted File Path vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context.

  • CVE-2022-33919HigOct 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell GeoDrive, versions 2.1 - 2.2, contains an information disclosure vulnerability in GUI. An authenticated non-admin user could potentially exploit this vulnerability and view sensitive information.

  • CVE-2022-26861HigSep 6, 2022
    risk 0.51cvss 7.9epss 0.00

    Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could exploit this vulnerability by sending malicious input via SMI to obtain arbitrary code execution during SMM.

  • CVE-2022-34382HigSep 2, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges.

  • CVE-2022-32481HigJul 7, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appliance deployments. A lower-privileged authenticated user can chain docker commands to escalate privileges to root leading to complete system takeover.

  • CVE-2022-29092HigJun 10, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system.

  • CVE-2022-24411HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE could potentially exploit this vulnerability, leading to elevation of privilege. This could potentially allow users to…

Page 9 of 35