Skip to main content

Vendor archive

dell CVEs

Beta · best-effort

1,585 CVEs tagged to vendor dell98 Critical, 655 High, 739 Medium, 93 Low, 0 Unrated.

CVE-2024-45765

Published Nov 8, 2024

Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high p…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45764

Published Nov 8, 2024

Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could potenti…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-48011

Published Nov 8, 2024

Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with remote acces…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-48010

Published Nov 8, 2024

Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45759

Published Nov 8, 2024

Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A local low privileged attacker co…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47483

Published Oct 25, 2024

Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthent…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-47481

Published Oct 25, 2024

Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated attacker with adjacent network access could potentially ex…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48016

Published Oct 18, 2024

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. A low privileged attacker with r…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47241

Published Oct 18, 2024

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper Certificate Validation vulnerability. A low privileged attacker with remote access cou…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47240

Published Oct 18, 2024

Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A local attacker with low privileges can access the file system and could potential…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45767

Published Oct 17, 2024

Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45766

Published Oct 17, 2024

Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A low privileged attacker with rem…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39586

Published Oct 9, 2024

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerab…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-39577

Published Sep 26, 2024

Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vu…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37125

Published Sep 26, 2024

Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consumption vulnerability. A remote unauthenticated host could po…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42423

Published Sep 10, 2024

Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated use…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39583

Published Sep 10, 2024

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access coul…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39582

Published Sep 10, 2024

Dell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerab…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-39581

Published Sep 10, 2024

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access co…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39580

Published Sep 10, 2024

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with local access could potentially exploit this…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39574

Published Sep 10, 2024

Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnera…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42427

Published Sep 10, 2024

Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39585

Published Sep 6, 2024

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote a…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort
Showing 451-475 of 1,585 CVEsPage 19 of 64