Vulnerabilities > Dell > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-02-10 CVE-2022-34366 Incorrect Comparison vulnerability in Dell Supportassist for Home PCS
Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability.
network
low complexity
dell CWE-697
6.5
2023-02-10 CVE-2022-34376 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products
Dell PowerEdge BIOS and Dell Precision BIOS contain an improper input validation vulnerability.
local
low complexity
dell CWE-119
5.5
2023-02-10 CVE-2022-34377 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell products
Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability.
local
low complexity
dell CWE-119
6.7
2023-02-10 CVE-2022-24410 Cleartext Storage of Sensitive Information vulnerability in Dell products
Dell BIOS contains an information exposure vulnerability.
high complexity
dell CWE-312
4.2
2023-02-10 CVE-2022-34454 Out-of-bounds Write vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow.
local
low complexity
dell CWE-787
6.7
2023-02-01 CVE-2023-22573 Information Exposure Through Log Files vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool.
local
low complexity
dell CWE-532
5.5
2023-02-01 CVE-2022-32482 Improper Input Validation vulnerability in Dell products
Dell BIOS contains an improper input validation vulnerability.
local
low complexity
dell CWE-20
5.1
2023-02-01 CVE-2022-45098 Cleartext Storage of Sensitive Information vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component.
local
low complexity
dell CWE-312
5.5
2023-02-01 CVE-2022-45102 Improper Encoding or Escaping of Output vulnerability in Dell products
Dell EMC Data Protection Central, versions 19.1 through 19.7, contains a Host Header Injection vulnerability.
network
low complexity
dell CWE-116
6.1
2023-02-01 CVE-2022-46756 Exposure of Resource to Wrong Sphere vulnerability in Dell Vxrail Manager
Dell VxRail, versions prior to 7.0.410, contain a Container Escape Vulnerability.
local
low complexity
dell CWE-668
6.7