Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2022-09-06 CVE-2022-26860 Out-of-bounds Write vulnerability in Dell products
Dell BIOS versions contain a stack-based buffer overflow vulnerability.
local
low complexity
dell CWE-787
7.8
2022-09-06 CVE-2022-26861 Unspecified vulnerability in Dell products
Dell BIOS versions contain an Insecure Automated Optimization vulnerability.
local
low complexity
dell
7.8
2022-09-02 CVE-2022-34369 Information Exposure Through Log Files vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability.
network
low complexity
dell CWE-532
7.5
2022-09-02 CVE-2022-34371 Insufficiently Protected Credentials vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability.
network
low complexity
dell CWE-522
critical
9.8
2022-09-02 CVE-2022-34378 Path Traversal vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability.
local
low complexity
dell CWE-22
5.5
2022-09-02 CVE-2022-34382 Unspecified vulnerability in Dell Alienware Update, Command Update and Update
Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration.
local
low complexity
dell
7.8
2022-09-01 CVE-2022-34372 Improper Authentication vulnerability in Dell Powerprotect Cyber Recovery
Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability.
network
low complexity
dell CWE-287
critical
9.1
2022-09-01 CVE-2022-34379 Improper Authentication vulnerability in Dell Cloudlink
Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability.
network
low complexity
dell CWE-287
critical
9.8
2022-09-01 CVE-2022-34380 Improper Authentication vulnerability in Dell Cloudlink
Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability.
local
low complexity
dell CWE-287
8.2
2022-08-31 CVE-2022-31233 Incorrect Resource Transfer Between Spheres vulnerability in Dell products
Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability.
low complexity
dell CWE-669
8.0