Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2021-08-09 CVE-2021-21585 OS Command Injection vulnerability in Dell Openmanage Enterprise 3.5
Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tools.
network
low complexity
dell CWE-78
7.2
2021-08-09 CVE-2021-21596 Unspecified vulnerability in Dell products
Dell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remote code execution vulnerability.
low complexity
dell
8.8
2021-08-09 CVE-2021-36276 Unspecified vulnerability in Dell Dbutildrv2.Sys Firmware 2.5/2.6
Dell DBUtilDrv2.sys driver (versions 2.5 and 2.6) contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure.
local
low complexity
dell
7.8
2021-08-09 CVE-2021-36277 Improper Verification of Cryptographic Signature vulnerability in Dell products
Dell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature Vulnerability.
local
low complexity
dell CWE-347
7.8
2021-08-03 CVE-2021-21576 Cross-site Scripting vulnerability in Dell EMC Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability.
network
low complexity
dell CWE-79
6.1
2021-08-03 CVE-2021-21577 Cross-site Scripting vulnerability in Dell EMC Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability.
network
low complexity
dell CWE-79
6.1
2021-08-03 CVE-2021-21578 Open Redirect vulnerability in Dell EMC Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability.
network
low complexity
dell CWE-601
6.1
2021-08-03 CVE-2021-21579 Open Redirect vulnerability in Dell EMC Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability.
network
low complexity
dell CWE-601
6.1
2021-08-03 CVE-2021-21580 Injection vulnerability in Dell EMC Idrac8 Firmware and EMC Idrac9 Firmware
Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate.
network
low complexity
dell CWE-74
4.3
2021-08-03 CVE-2021-21581 Cross-site Scripting vulnerability in Dell EMC Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability.
network
low complexity
dell CWE-79
6.1