Vulnerabilities > Dell > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-22 CVE-2023-39251 Unspecified vulnerability in Dell products
Dell BIOS contains an Improper Input Validation vulnerability.
local
low complexity
dell
6.7
2023-12-22 CVE-2023-43088 Unspecified vulnerability in Dell Precision 7865 Tower Firmware
Dell Client BIOS contains a pre-boot direct memory access (DMA) vulnerability.
low complexity
dell
6.8
2023-12-18 CVE-2023-28053 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell EMC Networker
Dell NetWorker Virtual Edition versions 19.8 and below contain the use of deprecated cryptographic algorithms in the SSH component.
network
low complexity
dell CWE-327
5.3
2023-12-14 CVE-2023-44278 Path Traversal vulnerability in Dell products
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability.
local
low complexity
dell CWE-22
6.7
2023-12-14 CVE-2023-44279 OS Command Injection vulnerability in Dell products
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI.
local
low complexity
dell CWE-78
6.7
2023-12-14 CVE-2023-44284 SQL Injection vulnerability in Dell products
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability.
network
low complexity
dell CWE-89
4.3
2023-12-14 CVE-2023-44286 Cross-site Scripting vulnerability in Dell products
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability.
network
low complexity
dell CWE-79
6.1
2023-12-14 CVE-2023-48661 Files or Directories Accessible to External Parties vulnerability in Dell products
Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability.
network
low complexity
dell CWE-552
4.9
2023-12-14 CVE-2023-48668 OS Command Injection vulnerability in Dell Powerprotect Data Domain Management Center
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 on DDMC contain an OS command injection vulnerability in an admin operation.
local
low complexity
dell CWE-78
6.7
2023-12-05 CVE-2023-44297 Improper Locking vulnerability in Dell products
Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability.
low complexity
dell CWE-667
6.8