Vulnerabilities > Dell > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-02-17 CVE-2023-23695 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell Secure Connect Gateway 5.12.00.10/5.14.00.12
Dell Secure Connect Gateway (SCG) version 5.14.00.12 contains a broken cryptographic algorithm vulnerability.
network
high complexity
dell CWE-327
5.9
2023-02-14 CVE-2022-22564 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell products
Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm.
network
high complexity
dell CWE-327
5.9
2023-02-13 CVE-2022-34397 Unspecified vulnerability in Dell products
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.
low complexity
dell
5.7
2023-02-11 CVE-2022-34385 Inadequate Encryption Strength vulnerability in Dell products
SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability.
local
low complexity
dell CWE-326
5.5
2023-02-11 CVE-2022-34386 Use of Hard-coded Credentials vulnerability in Dell products
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability.
local
low complexity
dell CWE-798
5.5
2023-02-11 CVE-2022-34389 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell products
Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component.
network
low complexity
dell CWE-307
5.3
2023-02-11 CVE-2022-34392 Insufficient Session Expiration vulnerability in Dell Supportassist for Home PCS
SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability.
local
low complexity
dell CWE-613
5.5
2023-02-11 CVE-2022-34404 Improper Certificate Validation vulnerability in Dell System Update 1.9/1.9.1
Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module.
local
low complexity
dell CWE-295
6.0
2023-02-11 CVE-2022-34445 Insufficiently Protected Credentials vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password.
local
low complexity
dell CWE-522
4.4
2023-02-11 CVE-2022-34449 Use of Hard-coded Credentials vulnerability in Dell Powerpath Management Appliance 3.2/3.3
PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability.
local
low complexity
dell CWE-798
6.0