Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2018-11-02 CVE-2018-11062 Use of Hard-coded Credentials vulnerability in Dell EMC Integrated Data Protection Appliance 2.0/2.1/2.2
Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with default passwords.
network
low complexity
dell CWE-798
8.8
2018-10-18 CVE-2018-15765 Information Exposure vulnerability in Dell EMC Secure Remote Services
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability.
local
low complexity
dell CWE-200
5.5
2018-10-11 CVE-2018-15766 Weak Password Requirements vulnerability in Dell Encryption and Endpoint Security Suite Enterprise
On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that device.
network
low complexity
dell CWE-521
7.5
2018-10-05 CVE-2018-11064 Incorrect Permission Assignment for Critical Resource vulnerability in Dell products
Dell EMC Unity OE versions 4.3.0.x and 4.3.1.x and UnityVSA OE versions 4.3.0.x and 4.3.1.x contains an Incorrect File Permissions vulnerability.
local
low complexity
dell CWE-732
7.8
2018-10-02 CVE-2018-11072 Uncontrolled Search Path Element vulnerability in Dell Digital Delivery
Dell Digital Delivery versions prior to 3.5.1 contain a DLL Injection Vulnerability.
local
low complexity
dell CWE-427
7.8
2018-09-28 CVE-2018-1251 Open Redirect vulnerability in Dell EMC Unity Firmware and EMC Unityvsa
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability.
network
low complexity
dell CWE-601
8.1
2018-09-28 CVE-2018-1250 Incorrect Authorization vulnerability in Dell EMC Unity Firmware and EMC Unityvsa
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability.
network
low complexity
dell CWE-863
6.5
2018-09-28 CVE-2018-1246 Cross-site Scripting vulnerability in Dell products
Dell EMC Unity and UnityVSA contains reflected cross-site scripting vulnerability.
network
low complexity
dell CWE-79
6.1
2018-09-14 CVE-2018-11058 Out-of-bounds Read vulnerability in multiple products
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data.
network
low complexity
dell oracle CWE-125
critical
9.8
2018-09-11 CVE-2018-11078 Incorrect Permission Assignment for Critical Resource vulnerability in Dell EMC Vplex Geosynchrony 5.4/5.5/6.0
Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability.
network
high complexity
dell CWE-732
7.5