Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Alienware M15 R6 Firmware MEDIUM 6.5
CVE-2021-21571

Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerab…

Fix: 1.3.3 / 1.4.0+
Fix from $1,600 2021-06-24
Poweredge R640 Firmware MEDIUM 6.7
CVE-2021-21554

Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and, Dell Precision 7920 Rack Workstation BIOS contain a stack-based buffer ov…

Fix: 2.9.4+
Fix from $1,600 2021-06-14
Poweredge R640 Firmware MEDIUM 6.7
CVE-2021-21555

Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a heap-based buffer overflow vulnerability in sys…

Fix: 2.11.2+
Fix from $1,600 2021-06-14
Poweredge R640 Firmware MEDIUM 6.7
CVE-2021-21556

Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a stack-based buffer overflow vulnerability in sy…

Fix: 2.11.2+
Fix from $1,600 2021-06-14
Poweredge R640 Firmware MEDIUM 6.7
CVE-2021-21557

Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high …

Fix: 2.11.2+
Fix from $1,600 2021-06-14
Emc Networker MEDIUM 5.3
CVE-2021-21559

Dell EMC NetWorker, versions 18.x, 19.1.x, 19.2.x 19.3.x, 19.4, and 19.4.0.1 contain an Improper Certificate Validation vulnerability in the client (…

Fix: 19.4.0.2+
Fix from $1,600 2021-06-08
Xtremio Management Server HIGH 8.8
CVE-2021-21549

Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged attacker could potentially ex…

Fix: 6.3.3-8+
Fix from $1,950 2021-05-21
Emc Integrated System For Microsoft Azure Stack Hub Firmware CRITICAL 9.8
CVE-2021-21505

Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticat…

Fix: after 2011
Fix from $2,300 2021-05-06
Emc Powerscale Onefs MEDIUM 6.7
CVE-2021-21527

Dell PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may …

Mitigation only
Fix from $1,600 2021-05-06
Emc Powerscale Onefs MEDIUM 6.7
CVE-2021-21550

Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability …

Mitigation only
Fix from $1,600 2021-05-06
Dbutil HIGH 7.8
CVE-2021-21551 KEVEPSS 53%

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or in…

Fix: after 2.3
Fix from $1,950 2021-05-04
X1008p Firmware CRITICAL 9.8
CVE-2021-21507

Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.82 contain…

Fix: 2.0.0.82 / 3.0.1.8+
Fix from $2,300 2021-04-30
Openmanage Enterprise Modular HIGH 8.8
CVE-2021-21530

Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authenticated malicious user with lo…

Fix: 1.30.00+
Fix from $1,950 2021-04-30
Idrac9 Firmware HIGH 8.1
CVE-2021-21540

Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a stack-based overflow vulnerability. A remote authenticated attacker could potentially exploit …

Fix: 4.40.00.00+
Fix from $1,950 2021-04-30
Solutions Enabler HIGH 7.8
CVE-2021-21531

Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monito…

Fix: 9.1.0.15 / 9.1.0.26+
Fix from $1,950 2021-04-30
Idrac9 Firmware HIGH 7.1
CVE-2021-21539

Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attack…

Fix: 4.40.00.00+
Fix from $1,950 2021-04-30
Unity Operating Environment MEDIUM 6.7
CVE-2021-21547

Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerability when the Dell Upgrade Read…

Fix: 5.0.7.0.5.008+
Fix from $1,600 2021-04-30
Idrac9 Firmware MEDIUM 6.1
CVE-2021-21541

Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a DOM-based cross-site scripting vulnerability. A remote unauthenticated attacker could potentia…

Fix: 4.40.00.00+
Fix from $1,600 2021-04-30
Hybrid Client HIGH 7.8
CVE-2021-21535

Dell Hybrid Client versions prior to 1.5 contain a missing authentication for a critical function vulnerability. A local unauthenticated attacker may…

Fix: 1.5+
Fix from $1,950 2021-04-30
Hybrid Client MEDIUM 5.5
CVE-2021-21536

Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerabili…

Fix: 1.5+
Fix from $1,600 2021-04-30
Hybrid Client MEDIUM 5.5
CVE-2021-21537

Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerabili…

Fix: 1.5+
Fix from $1,600 2021-04-30
Emc Powerscale Onefs CRITICAL 9.1
CVE-2020-26197

Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and…

Mitigation only
Fix from $2,300 2021-04-20
Powerscale Onefs MEDIUM 6.7
CVE-2021-21526

Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmin to execute arbitrary comman…

Fix: after 9.1.0
Fix from $1,600 2021-04-20
Storage Monitoring And Reporting CRITICAL 9.8
CVE-2021-21524

Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerability. A remote unauthenticate…

Fix: 4.5.0.1+
Fix from $2,300 2021-04-12
Peripheral Manager HIGH 7.8
CVE-2021-21545

Dell Peripheral Manager 1.3.1 or greater contains remediation for a local privilege escalation vulnerability that could be potentially exploited to g…

Fix: 1.3.1+
Fix from $1,950 2021-04-12
Wyse Thinos MEDIUM 6.3
CVE-2021-21532

Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redir…

Fix: 8.6+
Fix from $1,600 2021-04-02
System Update MEDIUM 5.5
CVE-2021-21529

Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malicious user with low privileges…

Fix: 1.9+
Fix from $1,600 2021-04-02
Supportassist Client Promanage HIGH 7.8
CVE-2021-21518

Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2…

Mitigation only
Fix from $1,950 2021-03-12
Idrac8 Firmware MEDIUM 6.1
CVE-2021-21510

Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit th…

Fix: 2.75.100.75+
Fix from $1,600 2021-03-08
Emc Powerscale Onefs HIGH 8.8
CVE-2021-21506

PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenticated with ISI_PRIV_SYS_SUPPO…

Mitigation only
Fix from $1,950 2021-03-08