Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-18571 Cross-site Scripting vulnerability in Dell RSA Identity Governance and Lifecycle
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL].
network
low complexity
dell CWE-79
5.4
2019-12-16 CVE-2019-18579 Unspecified vulnerability in Dell XPS 7390 Firmware 1.0.13/1.0.6/1.0.9
Settings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability.
low complexity
dell
6.8
2019-12-06 CVE-2019-18575 Uncontrolled Search Path Element vulnerability in Dell Command|Configure
Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability.
local
low complexity
dell CWE-427
7.1
2019-12-06 CVE-2019-19620 Improper Preservation of Permissions vulnerability in Dell RED Cloak Windows Agent
In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by removing NT AUTHORITY\SYSTEM permissions from a file.
local
low complexity
dell CWE-281
3.3
2019-12-03 CVE-2019-3750 Link Following vulnerability in Dell Command Update
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability.
local
low complexity
dell CWE-59
5.5
2019-12-03 CVE-2019-3749 Link Following vulnerability in Dell Command Update
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability.
local
low complexity
dell CWE-59
5.5
2019-11-26 CVE-2019-18580 Deserialization of Untrusted Data vulnerability in Dell EMC Storage Monitoring and Reporting 4.3.1
Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability.
network
low complexity
dell CWE-502
critical
10.0
2019-11-07 CVE-2019-3764 Unspecified vulnerability in Dell Idrac7 Firmware, Idrac8 Firmware and Idrac9 Firmware
Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability.
network
low complexity
dell
4.3
2019-10-14 CVE-2019-3767 Cleartext Storage of Sensitive Information vulnerability in Dell Imageassist
Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability.
local
low complexity
dell CWE-312
8.2
2019-10-09 CVE-2019-3765 Incorrect Permission Assignment for Critical Resource vulnerability in Dell products
Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4 contain an Incorrect Permission Assignment for Critical Resource vulnerability.
network
low complexity
dell CWE-732
8.1