Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2019-06-06 CVE-2019-3723 Improper Input Validation vulnerability in Dell EMC Openmanage Server Administrator
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability.
network
low complexity
dell CWE-20
critical
9.1
2019-06-06 CVE-2019-3722 XXE vulnerability in Dell EMC Openmanage Server Administrator
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability.
network
low complexity
dell CWE-611
7.5
2019-05-15 CVE-2019-3727 OS Command Injection vulnerability in Dell products
Dell EMC RecoverPoint versions prior to 5.1.3 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an OS command injection vulnerability in the installation feature of Boxmgmt CLI.
local
low complexity
dell CWE-78
6.7
2019-04-26 CVE-2019-3707 Unspecified vulnerability in Dell Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability.
network
low complexity
dell
critical
9.8
2019-04-26 CVE-2019-3706 Unspecified vulnerability in Dell Idrac9 Firmware 3.20.21.20/3.21.24.22/3.23.23.23
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability.
network
low complexity
dell
critical
9.8
2019-04-26 CVE-2019-3705 Out-of-bounds Write vulnerability in Dell products
Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability.
network
low complexity
dell CWE-787
critical
9.8
2019-04-25 CVE-2019-3721 Allocation of Resources Without Limits or Throttling vulnerability in Dell EMC Openmanage Server Administrator
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vulnerability.
network
low complexity
dell CWE-770
7.5
2019-04-25 CVE-2019-3720 Path Traversal vulnerability in Dell EMC Openmanage Server Administrator
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability.
network
low complexity
dell CWE-22
4.9
2019-04-18 CVE-2019-3719 Unspecified vulnerability in Dell Supportassist
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability.
low complexity
dell
8.0
2019-04-18 CVE-2019-3718 Cross-Site Request Forgery (CSRF) vulnerability in Dell Supportassist
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability.
network
low complexity
dell CWE-352
8.8