Vulnerabilities > Dell > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-23 CVE-2023-28071 Link Following vulnerability in Dell Alienware Update, Command Update and Update
Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability.
local
low complexity
dell CWE-59
7.1
2023-06-23 CVE-2023-28073 Improper Authentication vulnerability in Dell Latitude 5530 Firmware and Precision 3570 Firmware
Dell BIOS contains an improper authentication vulnerability.
local
low complexity
dell CWE-287
7.8
2023-06-23 CVE-2023-32463 Unspecified vulnerability in Dell products
Dell VxRail, version(s) 8.0.100 and earlier contain a denial-of-service vulnerability in the upgrade functionality.
network
low complexity
dell
7.5
2023-06-22 CVE-2023-32449 Improper Verification of Cryptographic Signature vulnerability in Dell Powerstoret OS
Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability.
local
low complexity
dell CWE-347
7.8
2023-06-14 CVE-2023-32465 Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability in Dell Powerprotect Cyber Recovery
Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability.
network
low complexity
dell CWE-644
8.8
2023-06-01 CVE-2023-28066 Improper Access Control vulnerability in Dell OS Recovery Tool 2.2.4013/2.3.7012.0
Dell OS Recovery Tool, versions 2.2.4013 and 2.3.7012.0, contain an Improper Access Control Vulnerability.
local
low complexity
dell CWE-284
7.8
2023-05-30 CVE-2023-28079 Incorrect Default Permissions vulnerability in Dell Powerpath 7.0/7.1/7.2
PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains Insecure File and Folder Permissions vulnerability.
local
low complexity
dell CWE-276
7.8
2023-05-30 CVE-2023-28080 Uncontrolled Search Path Element vulnerability in Dell Powerpath 7.0/7.1/7.2
PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities.
local
low complexity
dell CWE-427
7.3
2023-05-23 CVE-2023-23693 OS Command Injection vulnerability in Dell Vxrail Hyperconverged Infrastructure
Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility.
local
low complexity
dell CWE-78
8.2
2023-05-23 CVE-2023-23694 OS Command Injection vulnerability in Dell Vxrail Hyperconverged Infrastructure
Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager.
local
low complexity
dell CWE-78
7.8