Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2022-01-25 CVE-2021-36347 Out-of-bounds Write vulnerability in Dell products
iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability.
network
low complexity
dell CWE-787
7.2
2022-01-25 CVE-2021-36348 Injection vulnerability in Dell Integrated Dell Remote Access Controller 9 Firmware
iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability.
network
low complexity
dell CWE-74
8.1
2022-01-24 CVE-2021-36342 Improper Input Validation vulnerability in Dell products
Dell BIOS contains an improper input validation vulnerability.
local
low complexity
dell CWE-20
6.7
2022-01-24 CVE-2021-36343 Improper Input Validation vulnerability in Dell products
Dell BIOS contains an improper input validation vulnerability.
local
low complexity
dell CWE-20
6.7
2022-01-24 CVE-2021-36349 Server-Side Request Forgery (SSRF) vulnerability in Dell EMC Data Protection Central
Dell EMC Data Protection Central versions 19.5 and prior contain a Server Side Request Forgery vulnerability in the DPC DNS client processing.
network
low complexity
dell CWE-918
4.3
2022-01-24 CVE-2021-43588 Improper Input Validation vulnerability in Dell EMC Data Protection Central
Dell EMC Data Protection Central version 19.5 contains an Improper Input Validation Vulnerability.
network
low complexity
dell CWE-20
7.5
2022-01-24 CVE-2021-43589 OS Command Injection vulnerability in Dell products
Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability.
local
low complexity
dell CWE-78
6.7
2022-01-24 CVE-2022-22554 Insufficiently Protected Credentials vulnerability in Dell EMC System Update
Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability.
local
low complexity
dell CWE-522
5.5
2022-01-21 CVE-2021-36338 Reliance on Cookies without Validation and Integrity Checking vulnerability in Dell products
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability.
low complexity
dell CWE-565
8.0
2022-01-21 CVE-2021-36339 Unspecified vulnerability in Dell products
The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts.
local
low complexity
dell
7.8