← Back

Dell

dell

1,518 CVEs • 3,654 products

Products (3,654)

Click to collapse
Toggle

CVEs (1,518)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dell
1Emc Powerscale Onefs
Nov 21, 2024
Feb 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to informat...Show more
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and remote execution. Show less
1Dell
1Emc Powerscale Onefs
Nov 21, 2024
Feb 1, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could potentially exploit this vulnerability, leading to escalation of privileges, and informa...Show more
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could potentially exploit this vulnerability, leading to escalation of privileges, and information disclosure. Show less
1Dell
1Emc Powerscale Onefs
Nov 21, 2024
Feb 1, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenticated remote user could unintentionally lead an administrator to enable this vulnerability, leading to disclosure of inf...Show more
Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenticated remote user could unintentionally lead an administrator to enable this vulnerability, leading to disclosure of information. Show less
1Dell
1Emc Powerscale Onefs
Nov 21, 2024
Feb 1, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vuln...Show more
Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of service, information disclosure, and data deletion. Show less
1Dell
3Alienware Update
Command UpdateUpdate
Nov 21, 2024
Feb 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get applicable driver component. A local malicious user could potentially expl...Show more
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get applicable driver component. A local malicious user could potentially exploit this vulnerability leading to malicious payload execution. Show less
1Dell
3Alienware Update
Command UpdateUpdate
Nov 21, 2024
Feb 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local...Show more
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local malicious user could potentially exploit this vulnerability leading to the disclosure of confidential data. Show less
1Dell
1Rugged Control Center
Nov 21, 2024
Feb 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Rugged Control Center, versions prior to 4.5, contain an Improper Input Validation in the Service EndPoint. A Local Low Privilege attacker could potentially exploit this vulnerability, leading to an Escalation of p...Show more
Dell Rugged Control Center, versions prior to 4.5, contain an Improper Input Validation in the Service EndPoint. A Local Low Privilege attacker could potentially exploit this vulnerability, leading to an Escalation of privileges. Show less
1Dell
83Alienware M15 R6 Firmware
Alienware M15 R7 FirmwareAlienware M15 Ryzen Edition R5 Firmware+80 more
Nov 21, 2024
Feb 1, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM.
1Dell
1Realtek High Definition Audio Driver
Nov 21, 2024
Jan 26, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the applicati...Show more
An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the application and attach to the process to elevate privileges on the system. Show less
1Dell
3Powervault Me5012 Firmware
Powervault Me5024 FirmwarePowervault Me5084 Firmware
Nov 21, 2024
Jan 20, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Dell EMC PV ME5, versions ME5.1.0.0.0 and ME5.1.0.1.0, contains a Client-side desync Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability to force a victim's browser to desynchronize i...Show more
Dell EMC PV ME5, versions ME5.1.0.0.0 and ME5.1.0.1.0, contains a Client-side desync Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability to force a victim's browser to desynchronize its connection with the website, typically leading to XSS and DoS. Show less
1Dell
1Cloud Mobility For Dell Emc Storage
Nov 21, 2024
Jan 19, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation vulnerability. A threat actor does not need any specific privileges to potentially exploit this vulne...Show more
Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation vulnerability. A threat actor does not need any specific privileges to potentially exploit this vulnerability. An attacker could perform a man-in-the-middle attack and eavesdrop on encrypted communications from Cloud Mobility to Cloud Storage devices. Exploitation could lead to the compromise of secret and sensitive information, cloud storage connection downtime, and the integrity of the connection to the Cloud devices. Show less
1Dell
8Emc Solutions Enabler Virtual Appliance
Emc Unisphere For PowermaxEmc Unisphere For Powermax Virtual Appliance+5 more
Nov 21, 2024
Jan 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerabil...Show more
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system. Show less
1Dell
1Command|configure
Nov 21, 2024
Jan 18, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerabil...Show more
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users. Show less
1Dell
1Idrac8 Firmware
Nov 21, 2024
Jan 18, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability...Show more
Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update. Show less
1Dell
1Idrac9 Firmware
Nov 21, 2024
Jan 18, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability...Show more
Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update. Show less
1Dell
15Alienware M15 A6 Firmware
Alienware M15 Ryzen Edition R5 FirmwareAlienware M17 Ryzen Edition R5 Firmware+12 more
Nov 21, 2024
Jan 18, 2023
N/A· v4
2.3 LOW· v3
N/A· v2
Dell Alienware m17 R5 BIOS version prior to 1.2.2 contain a buffer access vulnerability. A malicious user with admin privileges could potentially exploit this vulnerability by sending input larger than expected in order...Show more
Dell Alienware m17 R5 BIOS version prior to 1.2.2 contain a buffer access vulnerability. A malicious user with admin privileges could potentially exploit this vulnerability by sending input larger than expected in order to leak certain sections of SMRAM. Show less
1Dell
1Policy Manager For Secure Connect Gateway
May 20, 2025
Jan 18, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to log...Show more
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges. Show less
1Dell
1Policy Manager For Secure Connect Gateway
May 20, 2025
Jan 18, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially expl...Show more
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges. Show less
1Dell
26G5 Se 5505 Firmware
Inspiron 27 7775 FirmwareInspiron 3180 Firmware+23 more
Nov 21, 2024
Jan 18, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Prior Dell BIOS versions contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM....Show more
Prior Dell BIOS versions contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. Show less
1Dell
1Emc Metro Node
Nov 21, 2024
Jan 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS comman...Show more
Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application. Show less