Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2023-02-01 CVE-2022-34398 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Dell products
Dell BIOS contains a Time-of-check Time-of-use vulnerability.
local
high complexity
dell CWE-367
7.0
2023-02-01 CVE-2022-34403 Out-of-bounds Write vulnerability in Dell products
Dell BIOS contains a Stack based buffer overflow vulnerability.
local
low complexity
dell CWE-787
8.8
2023-02-01 CVE-2022-45098 Cleartext Storage of Sensitive Information vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component.
local
low complexity
dell CWE-312
5.5
2023-02-01 CVE-2022-45099 Incorrect Default Permissions vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password.
local
low complexity
dell CWE-276
7.8
2023-02-01 CVE-2022-45100 Improper Certificate Validation vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability.
network
low complexity
dell CWE-295
critical
9.8
2023-02-01 CVE-2022-45102 Improper Encoding or Escaping of Output vulnerability in Dell products
Dell EMC Data Protection Central, versions 19.1 through 19.7, contains a Host Header Injection vulnerability.
network
low complexity
dell CWE-116
6.1
2023-02-01 CVE-2022-46679 Unspecified vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability.
network
low complexity
dell
7.5
2023-02-01 CVE-2022-46756 Exposure of Resource to Wrong Sphere vulnerability in Dell Vxrail Manager
Dell VxRail, versions prior to 7.0.410, contain a Container Escape Vulnerability.
local
low complexity
dell CWE-668
6.7
2023-02-01 CVE-2022-34400 Out-of-bounds Write vulnerability in Dell products
Dell BIOS contains a heap buffer overflow vulnerability.
local
low complexity
dell CWE-787
7.1
2023-02-01 CVE-2022-34443 Improper Input Validation vulnerability in Dell Rugged Control Center
Dell Rugged Control Center, versions prior to 4.5, contain an Improper Input Validation in the Service EndPoint.
local
low complexity
dell CWE-20
7.8