Vulnerabilities > Dell > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-04-02 CVE-2021-21533 Improper Input Validation vulnerability in Dell Wyse Management Suite
Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a denial of service in the job status retrieval page, also affecting other users that would have normally access to the same subset of job details
network
low complexity
dell CWE-20
4.3
2021-04-02 CVE-2021-21532 Improper Input Validation vulnerability in Dell Wyse Thinos 8.6
Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redirect a client to an attacker-controlled management server, thus allowing the attacker to change the device configuration or certificate file.
low complexity
dell CWE-20
6.3
2021-04-02 CVE-2021-21529 Resource Exhaustion vulnerability in Dell System Update
Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability.
local
low complexity
dell CWE-400
5.5
2021-03-08 CVE-2021-21510 Injection vulnerability in Dell Idrac8 Firmware
Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability.
network
low complexity
dell CWE-74
6.1
2021-03-02 CVE-2021-21514 Path Traversal vulnerability in Dell Openmanage Server Administrator
Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability.
network
low complexity
dell CWE-22
4.9
2021-03-01 CVE-2021-21515 Cross-site Scripting vulnerability in Dell EMC Sourceone 7.2
Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability.
network
low complexity
dell CWE-79
5.4
2021-02-19 CVE-2021-21512 Information Exposure vulnerability in Dell EMC Powerprotect Cyber Recovery 19.7.0.1
Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability.
local
low complexity
dell CWE-200
6.0
2021-02-09 CVE-2020-26196 Incorrect Permission Assignment for Critical Resource vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation issue.
local
low complexity
dell CWE-732
5.5
2021-02-09 CVE-2020-26195 Improper Handling of Exceptional Conditions vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto-create may erroneously create a directory for a user.
network
low complexity
dell CWE-755
5.3
2021-01-08 CVE-2020-26186 Exposure of Resource to Wrong Sphere vulnerability in Dell Inspiron 5675 Firmware
Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability.
low complexity
dell CWE-668
6.8