Vulnerabilities > Dell > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-04-09 CVE-2018-1217 Missing Authorization vulnerability in Dell products
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials.
network
low complexity
dell CWE-862
critical
9.8
2018-03-27 CVE-2018-1237 Improper Authentication vulnerability in Dell EMC Scaleio
Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LIA).
network
low complexity
dell CWE-287
critical
9.8
2018-03-23 CVE-2018-1207 Code Injection vulnerability in Dell EMC Idrac7 and EMC Idrac8
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code.
network
low complexity
dell CWE-94
critical
9.8
2018-03-08 CVE-2018-1216 Use of Hard-coded Credentials vulnerability in Dell products
A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.21, Dell EMC VASA Virtual Appliance versions prior to 8.4.0.514, and Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier).
network
low complexity
dell CWE-798
critical
9.8
2017-12-06 CVE-2017-14374 Use of Hard-coded Credentials vulnerability in Dell Storage Manager
The SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password.
network
low complexity
dell CWE-798
critical
9.8
2017-11-01 CVE-2017-14375 Authentication Bypass by Spoofing vulnerability in multiple products
EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier) contain an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system.
network
low complexity
emc dell CWE-290
critical
9.8
2017-10-03 CVE-2017-8021 Insecure Default Initialization of Resource vulnerability in Dell Elastic Cloud Storage 3.0
EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability that could potentially be leveraged by malicious users to compromise the affected system.
network
low complexity
dell CWE-1188
critical
9.8
2017-07-17 CVE-2017-8011 Use of Hard-coded Credentials vulnerability in Dell products
EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with default passwords for Webservice Gateway and RMI JMX components.
network
low complexity
dell CWE-798
critical
9.8
2017-06-29 CVE-2017-4997 Improper Input Validation vulnerability in Dell EMC Vasa Provider Virtual Appliance 8.3.0
EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code execution vulnerability that could potentially be exploited by malicious users to compromise the affected system.
network
low complexity
dell CWE-20
critical
9.8
2017-04-10 CVE-2015-7273 XXE vulnerability in Dell Integrated Remote Access Controller Firmware 1.99/2.20.20.20
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.
network
low complexity
dell CWE-611
critical
9.8