Vulnerabilities > Dell > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-44298 Improper Locking vulnerability in Dell products
Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability.
low complexity
dell CWE-667
6.8
2023-12-04 CVE-2023-44300 Insufficiently Protected Credentials vulnerability in Dell Powerprotect Data Manager Dm5500 Firmware
Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance.
local
low complexity
dell CWE-522
5.5
2023-12-04 CVE-2023-44301 Cross-site Scripting vulnerability in Dell Powerprotect Data Manager Dm5500 Firmware
Dell DM5500 5.14.0.0 and prior contain a Reflected Cross-Site Scripting Vulnerability.
network
low complexity
dell CWE-79
5.4
2023-12-04 CVE-2023-44306 Path Traversal vulnerability in Dell Dm5500 Firmware 5.14.0.0
Dell DM5500 contains a path traversal vulnerability in the appliance.
network
low complexity
dell CWE-22
6.5
2023-11-22 CVE-2023-43082 Improper Certificate Validation vulnerability in Dell products
Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component.
network
high complexity
dell CWE-295
5.9
2023-11-16 CVE-2023-32469 Improper Input Validation vulnerability in Dell products
Dell Precision Tower BIOS contains an Improper Input Validation vulnerability.
local
low complexity
dell CWE-20
6.7
2023-11-16 CVE-2023-44296 Use of Hard-coded Credentials vulnerability in Dell E-Lab Navigator 3.1.8/3.1.9
Dell ELab-Navigator, version 3.1.9 contains a hard-coded credential vulnerability.
local
low complexity
dell CWE-798
5.5
2023-11-02 CVE-2023-43076 Memory Leak vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability.
network
low complexity
dell CWE-401
6.5
2023-11-02 CVE-2023-43087 Improper Handling of Exceptional Conditions vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions.
network
low complexity
dell CWE-755
6.5
2023-10-23 CVE-2023-43067 XXE vulnerability in Dell products
Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability.
network
low complexity
dell CWE-611
6.5