Vulnerabilities > Dell

DATE CVE VULNERABILITY TITLE RISK
2020-02-06 CVE-2020-5318 Incorrect Authorization vulnerability in Dell EMC Isilon Onefs
Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations.
network
low complexity
dell CWE-863
7.5
2020-02-06 CVE-2020-5317 Cross-site Scripting vulnerability in Dell EMC Elastic Cloud Storage 3.4.0.0
Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability.
network
low complexity
dell CWE-79
4.8
2020-01-30 CVE-2015-0949 Improper Privilege Management vulnerability in multiple products
The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revision L71 Ver.
local
low complexity
dell hp CWE-269
7.8
2020-01-15 CVE-2009-1120 Unspecified vulnerability in Dell EMC Replistor
EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability.
network
low complexity
dell
critical
9.8
2020-01-10 CVE-2019-18588 Cross-site Scripting vulnerability in Dell EMC Powermax and EMC Unisphere for Powermax
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability.
network
low complexity
dell CWE-79
5.4
2019-12-18 CVE-2019-18573 Session Fixation vulnerability in Dell RSA Identity Governance and Lifecycle
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability.
network
low complexity
dell CWE-384
8.8
2019-12-18 CVE-2019-18572 Insufficiently Protected Credentials vulnerability in Dell RSA Identity Governance and Lifecycle
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability.
network
low complexity
dell CWE-522
critical
9.8
2019-12-18 CVE-2019-18571 Cross-site Scripting vulnerability in Dell RSA Identity Governance and Lifecycle
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL].
network
low complexity
dell CWE-79
5.4
2019-12-16 CVE-2019-18579 Unspecified vulnerability in Dell XPS 7390 Firmware 1.0.13/1.0.6/1.0.9
Settings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability.
low complexity
dell
6.8
2019-12-06 CVE-2019-18575 Uncontrolled Search Path Element vulnerability in Dell Command|Configure
Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability.
local
low complexity
dell CWE-427
7.1