Vulnerabilities > Dell > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-22 CVE-2023-43082 Improper Certificate Validation vulnerability in Dell products
Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component.
network
high complexity
dell CWE-295
5.9
2023-11-16 CVE-2023-32469 Improper Input Validation vulnerability in Dell products
Dell Precision Tower BIOS contains an Improper Input Validation vulnerability.
local
low complexity
dell CWE-20
6.7
2023-11-16 CVE-2023-44296 Use of Hard-coded Credentials vulnerability in Dell E-Lab Navigator 3.1.8/3.1.9
Dell ELab-Navigator, version 3.1.9 contains a hard-coded credential vulnerability.
local
low complexity
dell CWE-798
5.5
2023-11-02 CVE-2023-43076 Memory Leak vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability.
network
low complexity
dell CWE-401
6.5
2023-11-02 CVE-2023-43087 Improper Handling of Exceptional Conditions vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions.
network
low complexity
dell CWE-755
6.5
2023-10-23 CVE-2023-43067 XXE vulnerability in Dell products
Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability.
network
low complexity
dell CWE-611
6.5
2023-10-23 CVE-2023-43065 Cross-site Scripting vulnerability in Dell products
Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability.
network
low complexity
dell CWE-79
5.4
2023-10-05 CVE-2023-43070 Path Traversal vulnerability in Dell Smartfabric Storage Software 1.0.0/1.4.0
Dell SmartFabric Storage Software v1.4 (and earlier) contains a Path Traversal Vulnerability in the HTTP interface.
network
low complexity
dell CWE-22
6.5
2023-10-05 CVE-2023-43071 Improper Neutralization of Formula Elements in a CSV File vulnerability in Dell Smartfabric Storage Software 1.0.0/1.4.0
Dell SmartFabric Storage Software v1.4 (and earlier) contains possible vulnerabilities for HTML injection or CVS formula injection which might escalate to cross-site scripting attacks in HTML pages in the GUI.
network
low complexity
dell CWE-1236
5.4
2023-10-05 CVE-2023-43073 Improper Input Validation vulnerability in Dell Smartfabric Storage Software 1.0.0/1.4.0
Dell SmartFabric Storage Software v1.4 (and earlier) contains an Improper Input Validation vulnerability in RADIUS configuration.
network
low complexity
dell CWE-20
6.5