Vulnerabilities > Dell > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-08-10 CVE-2021-21600 Missing Release of Resource after Effective Lifetime vulnerability in Dell EMC Networker
Dell EMC NetWorker, 19.4 or older, contain an uncontrolled resource consumption flaw in its API service.
network
low complexity
dell CWE-772
6.5
2021-08-09 CVE-2021-21584 Information Exposure vulnerability in Dell products
Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability.
network
low complexity
dell CWE-200
6.5
2021-08-03 CVE-2021-21576 Cross-site Scripting vulnerability in Dell EMC Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability.
network
low complexity
dell CWE-79
6.1
2021-08-03 CVE-2021-21577 Cross-site Scripting vulnerability in Dell EMC Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability.
network
low complexity
dell CWE-79
6.1
2021-08-03 CVE-2021-21578 Open Redirect vulnerability in Dell EMC Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability.
network
low complexity
dell CWE-601
6.1
2021-08-03 CVE-2021-21579 Open Redirect vulnerability in Dell EMC Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability.
network
low complexity
dell CWE-601
6.1
2021-08-03 CVE-2021-21580 Injection vulnerability in Dell EMC Idrac8 Firmware and EMC Idrac9 Firmware
Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate.
network
low complexity
dell CWE-74
4.3
2021-08-03 CVE-2021-21581 Cross-site Scripting vulnerability in Dell EMC Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability.
network
low complexity
dell CWE-79
6.1
2021-08-03 CVE-2021-21562 Untrusted Search Path vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS contains an untrusted search path vulnerability.
local
low complexity
dell CWE-426
4.4
2021-08-03 CVE-2021-21563 Improper Check for Unusual or Exceptional Conditions vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its auditing component.This can lead to an authenticated user with low-privileges to trigger a denial of service event.
network
low complexity
dell CWE-754
6.5