Skip to main content

Vendor/product archive

dell / cloudlink CVEs

Beta · best-effort

16 CVEs tagged to dell / cloudlink6 Critical, 3 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2025-46424

Published Nov 5, 2025

Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerability. A high privileged attacker could potentially exploit thi…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46366

Published Nov 5, 2025

Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation or access to the database to obtain con…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46365

Published Nov 5, 2025

Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command Injection on an affected Dell…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46364

Published Nov 5, 2025

Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain control of system.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-45379

Published Nov 5, 2025

Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell access of system.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-45378

Published Nov 5, 2025

Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and g…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-30479

Published Nov 5, 2025

Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control of system.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26484

Published Aug 14, 2025

Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External Entity Reference vulnerability. A high privileged attacker with remote access could po…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-38482

Published Aug 2, 2024

CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privileged malicious user with remo…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37137

Published Jun 28, 2024

Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially explo…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-28076

Published May 16, 2023

CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerabi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34380

Published Sep 1, 2022

Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially e…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-34379

Published Sep 1, 2022

Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active directory usernames, could pote…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24414

Published May 26, 2022

Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests. These request parameters can get logged in reverse proxies and server logs. Attackers may…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36313

Published Nov 23, 2021

Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged attacker, may potentially exploit this vulnerability, leading…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-36312

Published Nov 23, 2021

Dell EMC CloudLink 7.1 and all prior versions contain a Hard-coded Password Vulnerability. A remote high privileged attacker, with the knowledge of the hard-coded credentials, may…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1