Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chengming 3980 Firmware MEDIUM 6.8
CVE-2022-29083

Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could poten…

Fix: 1.7.0 / 1.11.0+
Fix from $1,600 2022-08-09
Emc Data Protection Central HIGH 8.8
CVE-2022-34367

Dell EMC Data Protection Central versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, contain(s) a Cross-Site Request Forgery Vulnerability. A(n) remote unau…

Fix: 19.7+
Fix from $1,950 2022-07-21
Emc Powerstore 500t Firmware CRITICAL 9.8
CVE-2022-31234

Dell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI. A remote unauth…

Fix: 3.0.0.0-1732745+
Fix from $2,300 2022-07-21
Powerstore Command Line Interface HIGH 7.8
CVE-2022-32498

Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit this vulner…

Fix: 3.0.0.0-1732745+
Fix from $1,950 2022-07-21
Emc Powerstore 500t Firmware HIGH 7.8
CVE-2022-33923

Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attac…

Fix: 3.0.0.0-1732745+
Fix from $1,950 2022-07-21
Emc Powerstore 500t Firmware MEDIUM 6.7
CVE-2022-22555

Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, l…

Fix: 3.0.0.0-1732745+
Fix from $1,600 2022-07-21
Bsafe Crypto C Micro Edition HIGH 7.5
CVE-2020-29505

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Key Management Error V…

Fix: 4.1.5 / 4.5.2+
Fix from $1,950 2022-07-11
Cloud Mobility For Dell Emc Storage CRITICAL 9.8
CVE-2022-33936

Cloud Mobility for Dell EMC Storage, 1.3.0.XXX contains a RCE vulnerability. A non-privileged user could potentially exploit this vulnerability, lead…

Mitigation only
Fix from $2,300 2022-07-07
Powerprotect Cyber Recovery HIGH 7.8
CVE-2022-32481

Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appliance deployments. A lower-pri…

Fix: 19.11+
Fix from $1,950 2022-07-07
Powerscale Onefs CRITICAL 9.8
CVE-2022-31230

Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain broken or risky cryptographic algorithm. A remote unprivileged malicious attacker could potentia…

Fix: 9.3.0+
Fix from $2,300 2022-06-28
Wyse Management Suite MEDIUM 5.4
CVE-2022-29096

Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in saveGroupConfigurations page. An authenticated …

Fix: after 3.6.1
Fix from $1,600 2022-06-24
Alienware M15 R5 Firmware HIGH 7.8
CVE-2022-26862

Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerabili…

Fix: 1.2.1 / 1.4.4+
Fix from $1,950 2022-06-23
Alienware M15 R5 Firmware HIGH 7.8
CVE-2022-26863

Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerabili…

Fix: 1.2.1 / 1.4.4+
Fix from $1,950 2022-06-23
Alienware M15 R5 Firmware HIGH 7.8
CVE-2022-26864

Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerabili…

Fix: 1.2.1 / 1.4.4+
Fix from $1,950 2022-06-23
Supportassist For Business Pcs CRITICAL 9.6
CVE-2022-29095

Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-si…

Fix: after 3.10.4
Fix from $2,300 2022-06-10
Supportassist For Business Pcs HIGH 7.8
CVE-2022-29092

Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) …

Fix: after 3.11.0
Fix from $1,950 2022-06-10
Supportassist For Business Pcs HIGH 7.1
CVE-2022-29093

Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) …

Fix: after 3.10.4
Fix from $1,950 2022-06-10
Supportassist For Business Pcs HIGH 7.1
CVE-2022-29094

Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) …

Fix: after 3.10.4
Fix from $1,950 2022-06-10
Powerstoreos CRITICAL 9.8
CVE-2022-26869

Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploi…

Fix: 2.1.1.0+
Fix from $2,300 2022-06-02
Unity Operating Environment CRITICAL 9.8
CVE-2022-29084

Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remo…

Fix: 5.2.0.0.5.173+
Fix from $2,300 2022-06-02
Powerstoreos HIGH 8.0
CVE-2022-26867

PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitiz…

Fix: 2.1.1.0+
Fix from $1,950 2022-06-02
Powerstoreos HIGH 7.8
CVE-2022-22557

PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authent…

Fix: 2.1.0.0 / 2.1.1.0+
Fix from $1,950 2022-06-02
Powerstoreos HIGH 7.8
CVE-2022-26868

Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially ex…

Fix: 2.1.1.0+
Fix from $1,950 2022-06-02
Powerstoreos HIGH 7.5
CVE-2022-22556

Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker could pot…

Fix: 2.1.0.0 / 2.1.1.0+
Fix from $1,950 2022-06-02
Unity Operating Environment MEDIUM 6.7
CVE-2022-29085

Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-arr…

Fix: 5.2.0.0.5.173+
Fix from $1,600 2022-06-02
Powerstoreos MEDIUM 5.5
CVE-2022-26866

Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged network attacker could potentially …

Fix: 2.1.1.0+
Fix from $1,600 2022-06-02
Powerscale Onefs HIGH 7.5
CVE-2022-29098

Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account wit…

Patch available
Fix from $1,950 2022-06-01
Idrac9 CRITICAL 9.8
CVE-2022-24422EPSS 58%

Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacke…

Fix: 5.10.10.00+
Fix from $2,300 2022-05-26
Openmanage Enterprise HIGH 8.8
CVE-2022-26857

Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low p…

Fix: 3.8.4+
Fix from $1,950 2022-05-26
Supportassist Os Recovery MEDIUM 6.8
CVE-2022-26865

Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical acces…

Mitigation only
Fix from $1,600 2022-05-26