Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2022-06-02 CVE-2022-29084 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell products
Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI.
network
low complexity
dell CWE-307
critical
10.0
2022-06-02 CVE-2022-29085 Insufficiently Protected Credentials vulnerability in Dell products
Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system.
local
low complexity
dell CWE-522
4.6
2022-06-01 CVE-2020-26184 Improper Certificate Validation vulnerability in multiple products
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.
network
low complexity
dell oracle CWE-295
7.5
2022-06-01 CVE-2020-26185 Out-of-bounds Read vulnerability in multiple products
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability.
network
low complexity
dell oracle CWE-125
7.5
2022-06-01 CVE-2022-29098 Weak Password Requirements vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability.
network
low complexity
dell CWE-521
5.0
2022-05-26 CVE-2022-24414 Information Exposure vulnerability in Dell Cloudlink
Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests.
network
low complexity
dell CWE-200
4.0
2022-05-26 CVE-2022-24417 Improper Input Validation vulnerability in Dell products
Dell BIOS contains an improper input validation vulnerability.
local
low complexity
dell CWE-20
7.2
2022-05-26 CVE-2022-24418 Improper Input Validation vulnerability in Dell products
Dell BIOS contains an improper input validation vulnerability.
local
low complexity
dell CWE-20
7.2
2022-05-26 CVE-2022-24422 Improper Authentication vulnerability in Dell Idrac9
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability.
network
low complexity
dell CWE-287
critical
10.0
2022-05-26 CVE-2022-26857 Unspecified vulnerability in Dell Openmanage Enterprise 3.5/3.6.1
Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability.
network
low complexity
dell
8.8