Vulnerabilities > Dell > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-06-17 CVE-2020-11899 Out-of-bounds Read vulnerability in multiple products
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
low complexity
treck dell CWE-125
5.4
2020-06-10 CVE-2020-5363 Unspecified vulnerability in Dell products
Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password.
local
low complexity
dell
6.7
2020-06-10 CVE-2020-5362 Missing Authorization vulnerability in Dell products
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.
local
low complexity
dell CWE-862
4.4
2020-05-28 CVE-2020-5357 Uncontrolled Search Path Element vulnerability in Dell products
Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability.
local
high complexity
dell CWE-427
6.0
2020-03-13 CVE-2019-3770 Cross-site Scripting vulnerability in Dell Wyse Management Suite
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregistering a device.
network
low complexity
dell CWE-79
6.4
2020-03-13 CVE-2019-3769 Cross-site Scripting vulnerability in Dell Wyse Management Suite
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability.
network
low complexity
dell CWE-79
6.4
2020-03-13 CVE-2019-18577 Incorrect Permission Assignment for Critical Resource vulnerability in Dell Xtremio Management Server
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability.
local
low complexity
dell CWE-732
6.7
2020-03-13 CVE-2019-18576 Information Exposure Through Log Files vulnerability in Dell Xtremio Management Server
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files.
local
low complexity
dell CWE-532
6.7
2020-02-21 CVE-2020-5326 Missing Authentication for Critical Function vulnerability in Dell products
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu.
low complexity
dell CWE-306
5.3
2020-02-21 CVE-2020-5324 Link Following vulnerability in Dell products
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability.
local
high complexity
dell CWE-59
4.4