Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2017-05-04 CVE-2017-4983 Unspecified vulnerability in Dell EMC Data Domain OS
EMC Data Domain OS 5.2 through 5.7 before 5.7.3.0 and 6.0 before 6.0.1.0 is affected by a privilege escalation vulnerability that may potentially be exploited by attackers to compromise the affected system.
local
low complexity
dell
6.7
2017-04-10 CVE-2015-7275 Cross-site Scripting vulnerability in Dell Integrated Remote Access Controller Firmware
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS.
network
low complexity
dell CWE-79
6.1
2017-04-10 CVE-2015-7274 Permissions, Privileges, and Access Controls vulnerability in Dell Integrated Remote Access Controller Firmware 1.99
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrative HTTP commands.
network
low complexity
dell CWE-264
8.8
2017-04-10 CVE-2015-7273 XXE vulnerability in Dell Integrated Remote Access Controller Firmware 1.99/2.20.20.20
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.
network
low complexity
dell CWE-611
critical
9.8
2017-04-10 CVE-2015-7272 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell Integrated Remote Access Controller Firmware 1.99/2.20.20.20
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long SSH username or input.
network
low complexity
dell CWE-119
critical
9.8
2017-04-10 CVE-2015-7271 Use of Externally-Controlled Format String vulnerability in Dell Integrated Remote Access Controller Firmware 1.99/2.20.20.20
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo.
network
low complexity
dell CWE-134
critical
9.8
2017-04-10 CVE-2015-7270 Path Traversal vulnerability in Dell Integrated Remote Access Controller Firmware 1.99/2.20.20.20
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.
local
low complexity
dell CWE-22
7.8
2017-02-22 CVE-2016-9684 Command Injection vulnerability in Dell Sonicwall Secure Remote Access Server 8.1.0.214Sv
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface.
network
low complexity
dell CWE-77
critical
9.8
2017-02-22 CVE-2016-9683 Command Injection vulnerability in Dell Sonicwall Secure Remote Access Server 8.1.0.214Sv
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface.
network
low complexity
dell CWE-77
critical
9.8
2017-02-22 CVE-2016-9682 Command Injection vulnerability in Dell Sonicwall Secure Remote Access Server 8.1.0.214Sv
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface.
network
low complexity
dell CWE-77
critical
9.8