Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2022-06-02 CVE-2022-22556 Resource Exhaustion vulnerability in Dell Powerstoreos
Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface.
network
low complexity
dell CWE-400
7.5
2022-06-02 CVE-2022-22557 Insufficiently Protected Credentials vulnerability in Dell Powerstoreos
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials.
local
low complexity
dell CWE-522
7.8
2022-06-02 CVE-2022-26866 Cross-site Scripting vulnerability in Dell Powerstoreos
Dell PowerStore Versions before v2.1.1.0.
network
low complexity
dell CWE-79
5.5
2022-06-02 CVE-2022-26867 Improper Neutralization of Formula Elements in a CSV File vulnerability in Dell Powerstoreos
PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file.
network
low complexity
dell CWE-1236
8.0
2022-06-02 CVE-2022-26868 OS Command Injection vulnerability in Dell Powerstoreos
Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw.
local
low complexity
dell CWE-78
7.8
2022-06-02 CVE-2022-26869 Exposure of Resource to Wrong Sphere vulnerability in Dell Powerstoreos
Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability.
network
low complexity
dell CWE-668
critical
9.8
2022-06-02 CVE-2022-29084 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell products
Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI.
network
low complexity
dell CWE-307
critical
9.8
2022-06-02 CVE-2022-29085 Insufficiently Protected Credentials vulnerability in Dell products
Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system.
local
low complexity
dell CWE-522
6.7
2022-06-01 CVE-2020-26184 Improper Certificate Validation vulnerability in multiple products
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.
network
low complexity
dell oracle CWE-295
7.5
2022-06-01 CVE-2020-26185 Out-of-bounds Read vulnerability in multiple products
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability.
network
low complexity
dell oracle CWE-125
7.5