Vulnerabilities > Dell > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-04-08 CVE-2022-26854 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms.
network
low complexity
dell CWE-327
critical
10.0
2022-04-08 CVE-2021-36287 OS Command Injection vulnerability in Dell EMC Unity Operating Environment
Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system.
network
low complexity
dell CWE-78
critical
10.0
2022-04-01 CVE-2022-23155 Unrestricted Upload of File with Dangerous Type vulnerability in Dell Wyse Management Suite
Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability.
network
low complexity
dell CWE-434
critical
9.0
2022-02-09 CVE-2021-36302 Improper Privilege Management vulnerability in Dell EMC Integrated System for Microsoft Azure Stack HUB Firmware
All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability.
network
low complexity
dell CWE-269
critical
9.0
2022-01-25 CVE-2021-36347 Out-of-bounds Write vulnerability in Dell products
iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability.
network
low complexity
dell CWE-787
critical
9.0
2022-01-25 CVE-2021-36296 OS Command Injection vulnerability in Dell EMC Unity Operating Environment
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability.
network
low complexity
dell CWE-78
critical
9.0
2022-01-25 CVE-2021-36295 OS Command Injection vulnerability in Dell EMC Unity Operating Environment
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability.
network
low complexity
dell CWE-78
critical
9.0
2021-11-23 CVE-2021-36313 OS Command Injection vulnerability in Dell Cloudlink
Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability.
network
low complexity
dell CWE-78
critical
9.0
2021-11-20 CVE-2021-36308 Improper Authentication vulnerability in Dell Networking Os10
Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an authentication bypass vulnerability.
network
dell CWE-287
critical
9.3
2021-11-20 CVE-2021-36306 Improper Authentication vulnerability in Dell Networking Os10
Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerability.
network
dell CWE-287
critical
9.3