Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2024-06-25 CVE-2024-0171 Unspecified vulnerability in Dell products
Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability.
local
high complexity
dell
5.3
2024-06-25 CVE-2024-32855 Unspecified vulnerability in Dell products
Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component.
local
low complexity
dell
4.4
2024-06-13 CVE-2024-29169 Unspecified vulnerability in Dell Secure Connect Gateway
Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST API.
network
low complexity
dell
8.1
2024-06-13 CVE-2024-28965 Unspecified vulnerability in Dell Secure Connect Gateway 5.18.00.20/5.22.00.18
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabled by Admin user from UI).
network
low complexity
dell
5.4
2024-06-13 CVE-2024-28966 Unspecified vulnerability in Dell Secure Connect Gateway 5.18.00.20/5.22.00.18
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI).
network
low complexity
dell
5.4
2024-06-13 CVE-2024-28967 Unspecified vulnerability in Dell Secure Connect Gateway 5.18.00.20/5.22.00.18
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if enabled by Admin user from UI).
network
low complexity
dell
5.4
2024-06-13 CVE-2024-28968 Unspecified vulnerability in Dell Secure Connect Gateway 5.18.00.20/5.22.00.18
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for internal email and collection settings REST APIs (if enabled by Admin user from UI).
network
low complexity
dell
5.4
2024-06-13 CVE-2024-28969 Unspecified vulnerability in Dell Secure Connect Gateway 5.18.00.20/5.22.00.18
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI).
network
low complexity
dell
4.3
2024-06-13 CVE-2024-29168 Unspecified vulnerability in Dell Secure Connect Gateway 5.18.00.20/5.22.00.18
Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST API.
network
low complexity
dell
8.8
2024-06-13 CVE-2024-37131 Incorrect Comparison vulnerability in Dell Policy Manager for Secure Connect Gateway
SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability.
network
low complexity
dell CWE-697
critical
9.8