← Back

Dell

dell

1,518 CVEs • 3,654 products

Products (3,654)

Click to collapse
Toggle

CVEs (1,518)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dell
6Emc Powerconnect 7000 Firmware
Emc Powerconnect 8024 FirmwareEmc Powerconnect M6220 Firmware+3 more
Nov 21, 2024
Aug 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the...Show more
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.Show less
1Dell
1Digital Delivery
Nov 21, 2024
Aug 9, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a Universal Windows Platform application by manipulating the inst...Show more
Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a Universal Windows Platform application by manipulating the install software package feature with a race condition and a path traversal exploit in order to run a malicious executable with elevated privileges.Show less
1Dell
1Digital Delivery
Nov 21, 2024
Aug 9, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Dell/Alienware Digital Delivery versions prior to 3.5.2013 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a named pipe that performs binary deserialization via a process...Show more
Dell/Alienware Digital Delivery versions prior to 3.5.2013 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a named pipe that performs binary deserialization via a process hollowing technique to inject malicous code to run an executable with elevated privileges.Show less
1Dell
241Chengming 3967 Firmware
Chengming 3977 FirmwareChengming 3980 Firmware+238 more
Nov 21, 2024
Aug 5, 2019
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to...Show more
Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot. Refer to https://www.dell.com/support/article/us/en/04/sln317683/dsa-2019-043-dell-client-improper-access-control-vulnerability?lang=en for versions affected by this vulnerability.Show less
1Dell
2Emc Unity Operating Environment
Emc Unityvsa Operating Environment
Nov 21, 2024
Jul 18, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere user’s (including the admin privilege user) password is stored in a plain text in Unity Data Co...Show more
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere user’s (including the admin privilege user) password is stored in a plain text in Unity Data Collection bundle (logs files for troubleshooting). A local authenticated attacker with access to the Data Collection bundle may use the exposed password to gain access with the privileges of the compromised user.Show less
1Dell
2Emc Unity Operating Environment
Emc Unityvsa Operating Environment
Nov 21, 2024
Jul 18, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain an improper authorization vulnerability in NAS Server quotas configuration. A remote authenticated Unisphere Operator could potentially exploit this vul...Show more
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain an improper authorization vulnerability in NAS Server quotas configuration. A remote authenticated Unisphere Operator could potentially exploit this vulnerability to edit quota configuration of other users.Show less
2Dell
Pc Doctor
3Supportassist For Business Pcs
Supportassist For Home PcsToolbox
Nov 21, 2024
Jun 25, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element.
1Dell
2Supportassist For Business Pcs
Supportassist For Home Pcs
Nov 21, 2024
Jun 20, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malic...Show more
Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malicious local user can exploit this vulnerability by inheriting a system thread using a leaked thread handle to gain system privileges on the affected machine.Show less
1Dell
1Avamar Data Migration Enabler Web Interface
Nov 21, 2024
Jun 19, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially crafted request to th...Show more
Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially crafted request to the Web Interface application.Show less
1Dell
1Emc Openmanage Server Administrator
Nov 21, 2024
Jun 6, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of...Show more
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete the contents of any existing file, due to improper input parameter validationShow less
1Dell
1Emc Openmanage Server Administrator
Nov 21, 2024
Jun 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit thi...Show more
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.Show less
1Dell
2Emc Recoverpoint
Recoverpoint For Virtual Machines
Nov 21, 2024
May 15, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Dell EMC RecoverPoint versions prior to 5.1.3 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an OS command injection vulnerability in the installation feature of Boxmgmt CLI. A malicious boxmgmt user may pote...Show more
Dell EMC RecoverPoint versions prior to 5.1.3 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an OS command injection vulnerability in the installation feature of Boxmgmt CLI. A malicious boxmgmt user may potentially be able to execute arbitrary commands as root.Show less
1Dell
1Idrac9 Firmware
Nov 21, 2024
Apr 26, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending...Show more
Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted input data to the WS-MAN interface.Show less
1Dell
1Idrac9 Firmware
Nov 21, 2024
Apr 26, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication an...Show more
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted data to the iDRAC web interface.Show less
1Dell
4Idrac6 Firmware
Idrac7 FirmwareIdrac8 Firmware+1 more
Nov 21, 2024
Apr 26, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An u...Show more
Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the webserver or execute arbitrary code on the system with privileges of the webserver by sending specially crafted input data to the affected system.Show less
1Dell
1Emc Openmanage Server Administrator
Nov 21, 2024
Apr 25, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vulnerability. A remote unauthenticated attacker may send crafted requests with overlapping ranges to c...Show more
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vulnerability. A remote unauthenticated attacker may send crafted requests with overlapping ranges to cause the application to compress each of the requested bytes, resulting in a crash due to excessive memory consumption and preventing users from accessing the system.Show less
1Dell
1Emc Openmanage Server Administrator
Nov 21, 2024
Apr 25, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability. A remote authenticated malicious user with admin privileges could potentially exploit this vulnerabili...Show more
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability. A remote authenticated malicious user with admin privileges could potentially exploit this vulnerability to gain unauthorized access to the file system by exploiting insufficient sanitization of input parameters.Show less
1Dell
1Supportassist
Nov 21, 2024
Apr 18, 2019
N/A· v4
8.0 HIGH· v3
7.9 HIGH· v2
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable...Show more
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via SupportAssist client from attacker hosted sites.Show less
1Dell
1Supportassist
Nov 21, 2024
Apr 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users o...Show more
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users of the impacted systems.Show less
1Dell
1Emc Isilonsd Management Server
Nov 21, 2024
Apr 17, 2019
N/A· v4
9.6 CRITICAL· v3
9.3 HIGH· v2
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious H...Show more
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user.Show less