Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2017-02-22 CVE-2016-9683 Command Injection vulnerability in Dell Sonicwall Secure Remote Access Server 8.1.0.214Sv
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface.
network
low complexity
dell CWE-77
critical
9.8
2017-02-22 CVE-2016-9682 Command Injection vulnerability in Dell Sonicwall Secure Remote Access Server 8.1.0.214Sv
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface.
network
low complexity
dell CWE-77
critical
9.8
2017-02-21 CVE-2015-4057 Information Exposure vulnerability in Dell VCE Vision Intelligent Operations 2.5/2.6/2.6.4
The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon a request for the Settings screen, which allows remote attackers to discover the admin user password by sniffing the network.
network
low complexity
dell CWE-200
7.5
2017-02-21 CVE-2015-4056 Cryptographic Issues vulnerability in Dell VCE Vision Intelligent Operations 2.5/2.6/2.6.4
The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which makes it easier for local users to discover credentials by leveraging administrative access.
local
low complexity
dell CWE-310
6.7
2017-02-03 CVE-2016-8217 Information Exposure vulnerability in Dell Bsafe Crypto-J
EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability.
network
high complexity
dell CWE-200
3.7
2017-02-03 CVE-2016-8216 Permissions, Privileges, and Access Controls vulnerability in Dell EMC Data Domain OS
EMC Data Domain OS (DD OS) 5.4 all versions, EMC Data Domain OS (DD OS) 5.5 family all versions prior to 5.5.5.0, EMC Data Domain OS (DD OS) 5.6 family all versions prior to 5.6.2.0, EMC Data Domain OS (DD OS) 5.7 family all versions prior to 5.7.2.10 has a command injection vulnerability that could potentially be exploited by malicious users to compromise the affected system.
local
low complexity
dell CWE-264
6.7
2017-02-03 CVE-2016-8212 Improper Resource Shutdown or Release vulnerability in Dell Bsafe Crypto-J
An issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6.2.2.
network
low complexity
dell CWE-404
7.5
2017-02-03 CVE-2016-8211 Path Traversal vulnerability in Dell EMC Data Protection Advisor
EMC Data Protection Advisor 6.1.x, EMC Data Protection Advisor 6.2, EMC Data Protection Advisor 6.2.1, EMC Data Protection Advisor 6.2.2, EMC Data Protection Advisor 6.2.3 prior to patch 446 has a path traversal vulnerability that may potentially be exploited by malicious users to compromise the affected system.
network
low complexity
dell CWE-22
7.5
2016-11-29 CVE-2016-5685 Injection vulnerability in Dell Idrac7 Firmware and Idrac8 Firmware
Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.
network
low complexity
dell CWE-74
8.8
2016-10-05 CVE-2016-6646 Improper Input Validation vulnerability in multiple products
The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote attackers to execute arbitrary code via crafted input to the (1) GetSymmCmdRequest or (2) RemoteServiceHandler class.
network
low complexity
emc dell CWE-20
critical
9.8