Vulnerabilities > Dell > High

DATE CVE VULNERABILITY TITLE RISK
2019-09-30 CVE-2019-3728 Out-of-bounds Read vulnerability in Dell products
RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.4 (in 4.0.x) and 4.1.4 (in 4.1.x) and RSA BSAFE Micro Edition Suite versions prior to 4.0.13 (in 4.0.x) and prior to 4.4 (in 4.1.x, 4.2.x, 4.3.x) are vulnerable to a Buffer Over-read vulnerability when processing DSA signature.
network
low complexity
dell CWE-125
7.5
2019-09-27 CVE-2019-3746 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell EMC Integrated Data Protection Appliance Firmware 2.0/2.1/2.2
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts to the ACM API.
network
low complexity
dell CWE-307
8.8
2019-09-27 CVE-2019-3736 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell EMC Integrated Data Protection Appliance Firmware 2.0/2.1/2.2
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component.
network
low complexity
dell CWE-327
7.2
2019-09-11 CVE-2019-3763 Information Exposure Through Log Files vulnerability in Dell products
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain an information exposure vulnerability.
local
low complexity
dell CWE-532
7.8
2019-09-11 CVE-2019-3760 SQL Injection vulnerability in Dell products
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a SQL Injection vulnerability in Workflow Architect.
network
low complexity
dell CWE-89
8.8
2019-09-11 CVE-2019-3759 Code Injection vulnerability in Dell products
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability.
network
low complexity
dell CWE-94
8.1
2019-09-03 CVE-2019-3751 Improper Certificate Validation vulnerability in Dell EMC Enterprise Copy Data Management
Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vulnerability.
network
high complexity
dell CWE-295
7.4
2019-08-09 CVE-2019-3744 Race Condition vulnerability in Dell Digital Delivery
Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability.
local
low complexity
dell CWE-362
7.8
2019-08-09 CVE-2019-3742 Unspecified vulnerability in Dell Digital Delivery
Dell/Alienware Digital Delivery versions prior to 3.5.2013 contain a privilege escalation vulnerability.
local
low complexity
dell
7.8
2019-07-18 CVE-2019-3741 Protection Mechanism Failure vulnerability in Dell products
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability.
local
low complexity
dell CWE-693
7.8