Vulnerabilities > Dell > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-03-16 CVE-2022-34422 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products
Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability.
local
low complexity
dell CWE-119
6.7
2023-03-16 CVE-2023-24571 Improper Input Validation vulnerability in Dell Embedded BOX PC 3000 Firmware 1.16.0
Dell BIOS contains an Improper Input Validation vulnerability.
local
low complexity
dell CWE-20
6.7
2023-03-08 CVE-2022-46752 Unspecified vulnerability in Dell products
Dell BIOS contains an Improper Authorization vulnerability.
low complexity
dell
4.6
2023-03-02 CVE-2023-25536 Exposure of Resource to Wrong Sphere vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor.
local
low complexity
dell CWE-668
6.7
2023-03-01 CVE-2023-24567 Exposure of Resource to Wrong Sphere vulnerability in Dell EMC Networker
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability.
network
low complexity
dell CWE-668
6.5
2023-03-01 CVE-2023-25544 Exposure of Resource to Wrong Sphere vulnerability in Dell EMC Networker
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability.
network
low complexity
dell CWE-668
6.5
2023-02-17 CVE-2023-23695 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell Secure Connect Gateway 5.12.00.10/5.14.00.12
Dell Secure Connect Gateway (SCG) version 5.14.00.12 contains a broken cryptographic algorithm vulnerability.
network
high complexity
dell CWE-327
5.9
2023-02-14 CVE-2022-22564 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell products
Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm.
network
high complexity
dell CWE-327
5.9
2023-02-13 CVE-2022-34397 Unspecified vulnerability in Dell products
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.
low complexity
dell
5.7
2023-02-11 CVE-2022-34385 Inadequate Encryption Strength vulnerability in Dell products
SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability.
local
low complexity
dell CWE-326
5.5