Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2020-07-09 CVE-2020-5366 Path Traversal vulnerability in Dell Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability.
network
low complexity
dell CWE-22
6.5
2020-07-06 CVE-2020-5372 Incorrect Authorization vulnerability in Dell products
Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network.
network
low complexity
dell CWE-863
7.5
2020-07-06 CVE-2020-5371 Incorrect Permission Assignment for Critical Resource vulnerability in Dell EMC Isilon Onefs and EMC Powerscale Onefs
Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a file permissions vulnerability.
network
low complexity
dell CWE-732
8.8
2020-07-06 CVE-2020-5368 Missing Authorization vulnerability in Dell Vxrail D560 Firmware and Vxrail D560F Firmware
Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability.
network
low complexity
dell CWE-862
7.5
2020-07-06 CVE-2020-5356 Files or Directories Accessible to External Parties vulnerability in Dell products
Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability.
network
low complexity
dell CWE-552
6.5
2020-07-06 CVE-2020-5352 OS Command Injection vulnerability in Dell EMC Data Protection Advisor 18.1/6.4/6.5
Dell EMC Data Protection Advisor 6.4, 6.5 and 18.1 contain an OS command injection vulnerability.
network
low complexity
dell CWE-78
8.8
2020-06-23 CVE-2020-5367 Improper Certificate Validation vulnerability in Dell products
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability.
network
high complexity
dell CWE-295
8.1
2020-06-23 CVE-2020-5345 Missing Authorization vulnerability in Dell products
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability.
network
low complexity
dell CWE-862
5.4
2020-06-17 CVE-2020-11899 Out-of-bounds Read vulnerability in multiple products
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
low complexity
treck dell CWE-125
5.4
2020-06-15 CVE-2020-5358 Incorrect Permission Assignment for Critical Resource vulnerability in Dell Encryption and Endpoint Security Suite Enterprise
Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to incorrect permissions.
local
low complexity
dell CWE-732
7.8