Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2020-03-13 CVE-2019-3769 Cross-site Scripting vulnerability in Dell Wyse Management Suite
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability.
network
low complexity
dell CWE-79
6.4
2020-03-13 CVE-2019-18578 Cross-site Scripting vulnerability in Dell Xtremio Management Server
Dell EMC XtremIO XMS versions prior to 6.3.0 contain a stored cross-site scripting vulnerability.
network
low complexity
dell CWE-79
critical
9.0
2020-03-13 CVE-2019-18577 Incorrect Permission Assignment for Critical Resource vulnerability in Dell Xtremio Management Server
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability.
local
low complexity
dell CWE-732
6.7
2020-03-13 CVE-2019-18576 Information Exposure Through Log Files vulnerability in Dell Xtremio Management Server
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files.
local
low complexity
dell CWE-532
6.7
2020-03-09 CVE-2020-5342 Incorrect Default Permissions vulnerability in Dell Digital Delivery
Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability.
local
low complexity
dell CWE-276
7.8
2020-03-06 CVE-2020-5328 Missing Authentication for Critical Function vulnerability in Dell EMC Isilon Onefs
Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required.
network
low complexity
dell CWE-306
critical
9.8
2020-03-06 CVE-2020-5327 Deserialization of Untrusted Data vulnerability in Dell Security Management Server 10.2.0
Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability.
network
low complexity
dell CWE-502
critical
9.8
2020-02-21 CVE-2020-5326 Missing Authentication for Critical Function vulnerability in Dell products
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu.
low complexity
dell CWE-306
5.3
2020-02-21 CVE-2020-5324 Link Following vulnerability in Dell products
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability.
local
high complexity
dell CWE-59
4.4
2020-02-06 CVE-2020-5319 Improper Validation of Array Index vulnerability in Dell products
Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP service on a NAS server.
network
low complexity
dell CWE-129
7.5