Vulnerabilities > Dell > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-01-24 CVE-2024-22229 Improper Encoding or Escaping of Output vulnerability in Dell products
Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker.
network
low complexity
dell CWE-116
4.3
2023-12-22 CVE-2023-39251 Unspecified vulnerability in Dell products
Dell BIOS contains an Improper Input Validation vulnerability.
local
low complexity
dell
6.7
2023-12-22 CVE-2023-43088 Unspecified vulnerability in Dell Precision 7865 Tower Firmware
Dell Client BIOS contains a pre-boot direct memory access (DMA) vulnerability.
low complexity
dell
6.8
2023-12-18 CVE-2023-28053 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell EMC Networker
Dell NetWorker Virtual Edition versions 19.8 and below contain the use of deprecated cryptographic algorithms in the SSH component.
network
low complexity
dell CWE-327
5.3
2023-12-14 CVE-2023-44278 Path Traversal vulnerability in Dell products
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability.
local
low complexity
dell CWE-22
6.7
2023-12-14 CVE-2023-44279 OS Command Injection vulnerability in Dell products
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI.
local
low complexity
dell CWE-78
6.7
2023-12-14 CVE-2023-44284 SQL Injection vulnerability in Dell products
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability.
network
low complexity
dell CWE-89
4.3
2023-12-14 CVE-2023-44286 Cross-site Scripting vulnerability in Dell products
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability.
network
low complexity
dell CWE-79
6.1
2023-12-14 CVE-2023-48661 Files or Directories Accessible to External Parties vulnerability in Dell products
Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability.
network
low complexity
dell CWE-552
4.9
2023-12-14 CVE-2023-48668 OS Command Injection vulnerability in Dell Powerprotect Data Domain Management Center
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 on DDMC contain an OS command injection vulnerability in an admin operation.
local
low complexity
dell CWE-78
6.7