Vulnerabilities > Dell > High

DATE CVE VULNERABILITY TITLE RISK
2023-04-06 CVE-2023-25542 Incorrect Default Permissions vulnerability in Dell Trusted Device Agent
Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability.
local
low complexity
dell CWE-276
7.8
2023-04-04 CVE-2023-25941 Incorrect Default Permissions vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability.
local
low complexity
dell CWE-276
7.8
2023-04-04 CVE-2023-25940 Link Following vulnerability in Dell EMC Powerscale Onefs 9.5.0.0
Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info.
local
low complexity
dell CWE-59
7.8
2023-03-17 CVE-2021-21548 Improper Certificate Validation vulnerability in Dell products
Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability.
network
high complexity
dell CWE-295
7.4
2023-02-28 CVE-2023-23689 Resource Exhaustion vulnerability in Dell products
Dell PowerScale nodes A200, A2000, H400, H500, H600, H5600, F800, F810 integrated hardware management software contains an uncontrolled resource consumption vulnerability.
network
low complexity
dell CWE-400
7.5
2023-02-28 CVE-2023-25540 Incorrect Default Permissions vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability.
local
low complexity
dell CWE-276
7.1
2023-02-21 CVE-2023-24575 Unspecified vulnerability in Dell Multifunction Printer E525W Driver and Software Suite
Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system
local
low complexity
dell
7.8
2023-02-11 CVE-2022-34384 Improper Privilege Management vulnerability in Dell products
Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component.
local
low complexity
dell CWE-269
7.8
2023-02-11 CVE-2022-34387 Exposure of Resource to Wrong Sphere vulnerability in Dell products
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability.
local
low complexity
dell CWE-668
7.8
2023-02-11 CVE-2022-34388 Cleartext Storage of Sensitive Information vulnerability in Dell products
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability.
local
low complexity
dell CWE-312
7.1