Vulnerabilities > Dell > Xtremio Management Server

DATE CVE VULNERABILITY TITLE RISK
2022-10-12 CVE-2022-31228 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell Xtremio Management Server 6.3.0/6.3.38
Dell EMC XtremIO versions prior to X2 6.4.0-22 contain a bruteforce vulnerability.
network
low complexity
dell CWE-307
critical
9.8
2021-05-21 CVE-2021-21549 Cross-Site Request Forgery (CSRF) vulnerability in Dell Xtremio Management Server 6.3.0
Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS.
network
dell CWE-352
6.8
2020-03-13 CVE-2019-18578 Cross-site Scripting vulnerability in Dell Xtremio Management Server
Dell EMC XtremIO XMS versions prior to 6.3.0 contain a stored cross-site scripting vulnerability.
network
dell CWE-79
6.0
2020-03-13 CVE-2019-18577 Incorrect Permission Assignment for Critical Resource vulnerability in Dell Xtremio Management Server
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability.
local
low complexity
dell CWE-732
7.2
2020-03-13 CVE-2019-18576 Information Exposure Through Log Files vulnerability in Dell Xtremio Management Server
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files.
local
low complexity
dell CWE-532
2.1