Vulnerabilities > Dell > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-10-01 CVE-2021-36298 Unspecified vulnerability in Dell Isilon Insightiq Firmware
Dell EMC InsightIQ, versions prior to 4.1.4, contain risky cryptographic algorithms in the SSH component.
network
low complexity
dell
critical
9.8
2021-08-09 CVE-2021-21564 Improper Authentication vulnerability in Dell Openmanage Enterprise 3.5
Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability.
network
low complexity
dell CWE-287
critical
9.8
2021-07-29 CVE-2021-21538 Improper Authentication vulnerability in Dell Idrac9 Firmware 4.40.00.00
Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability.
network
low complexity
dell CWE-287
critical
10.0
2021-07-28 CVE-2020-5341 Deserialization of Untrusted Data vulnerability in Dell products
Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 and 2.4.1 contain a Deserialization of Untrusted Data Vulnerability.
network
low complexity
dell CWE-502
critical
9.8
2021-07-19 CVE-2020-5322 OS Command Injection vulnerability in Dell EMC Openmanage Enterprise-Modular
Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability.
network
low complexity
dell CWE-78
critical
9.1
2021-07-19 CVE-2020-5349 Use of Hard-coded Credentials vulnerability in Dell products
Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential vulnerability.
network
low complexity
dell CWE-798
critical
9.8
2021-05-06 CVE-2021-21505 Insecure Default Initialization of Resource vulnerability in Dell EMC Integrated System for Microsoft Azure Stack HUB Firmware 1906/2011
Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account.
network
low complexity
dell CWE-1188
critical
9.8
2021-04-30 CVE-2021-21507 Inadequate Encryption Strength vulnerability in Dell products
Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.82 contain a Weak Password Encryption Vulnerability.
network
low complexity
dell CWE-326
critical
9.8
2021-04-20 CVE-2020-26197 Cleartext Transmission of Sensitive Information vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability.
network
low complexity
dell CWE-319
critical
9.1
2021-04-12 CVE-2021-21524 Deserialization of Untrusted Data vulnerability in Dell products
Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerability.
network
low complexity
dell CWE-502
critical
9.8