Vulnerabilities > Dell > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-01-15 CVE-2009-1120 Unspecified vulnerability in Dell EMC Replistor
EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability.
network
low complexity
dell
critical
9.8
2019-12-18 CVE-2019-18572 Insufficiently Protected Credentials vulnerability in Dell RSA Identity Governance and Lifecycle
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability.
network
low complexity
dell CWE-522
critical
9.8
2019-11-26 CVE-2019-18580 Deserialization of Untrusted Data vulnerability in Dell EMC Storage Monitoring and Reporting 4.3.1
Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability.
network
low complexity
dell CWE-502
critical
10.0
2019-09-27 CVE-2019-3766 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell EMC Elastic Cloud Storage
Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerability.
network
low complexity
dell CWE-307
critical
9.8
2019-06-06 CVE-2019-3723 Improper Input Validation vulnerability in Dell EMC Openmanage Server Administrator
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability.
network
low complexity
dell CWE-20
critical
9.1
2019-04-26 CVE-2019-3707 Unspecified vulnerability in Dell Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability.
network
low complexity
dell
critical
9.8
2019-04-26 CVE-2019-3706 Unspecified vulnerability in Dell Idrac9 Firmware 3.20.21.20/3.21.24.22/3.23.23.23
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability.
network
low complexity
dell
critical
9.8
2019-04-26 CVE-2019-3705 Out-of-bounds Write vulnerability in Dell products
Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability.
network
low complexity
dell CWE-787
critical
9.8
2019-04-17 CVE-2019-3709 Cross-site Scripting vulnerability in Dell EMC Isilonsd Management Server 1.1.0
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers.
network
low complexity
dell CWE-79
critical
9.6
2019-04-17 CVE-2019-3708 Cross-site Scripting vulnerability in Dell EMC Isilonsd Management Server 1.1.0
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file.
network
low complexity
dell CWE-79
critical
9.6