Show filters
43 Total Results
Displaying 11-20 of 43
Sort by:
Attacker Value
Unknown

CVE-2024-39585

Disclosure Date: September 06, 2024 (last updated September 14, 2024)
Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and Information disclosure.
Attacker Value
Unknown

CVE-2024-38486

Disclosure Date: September 06, 2024 (last updated September 14, 2024)
Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Attacker Value
Unknown

CVE-2023-32462

Disclosure Date: February 15, 2024 (last updated January 24, 2025)
Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands and possible system takeover. This is a critical vulnerability as it allows an attacker to cause severe damage. Dell recommends customers to upgrade at the earliest opportunity.
Attacker Value
Unknown

CVE-2023-28078

Disclosure Date: February 15, 2024 (last updated January 24, 2025)
Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge number of requests are sent to the switch. This is a high severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity.
Attacker Value
Unknown

CVE-2023-28531

Disclosure Date: March 17, 2023 (last updated October 08, 2023)
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
Attacker Value
Unknown

CVE-2022-34394

Disclosure Date: September 01, 2022 (last updated October 08, 2023)
Dell OS10, version 10.5.3.4, contains an Improper Certificate Validation vulnerability in Support Assist. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to limited switch configuration data. The vulnerability could be leveraged by attackers to conduct man-in-the-middle attacks to gain access to the Support Assist information.
Attacker Value
Unknown

CVE-2022-34424

Disclosure Date: September 01, 2022 (last updated October 08, 2023)
Networking OS10, versions 10.5.1.x, 10.5.2.x, and 10.5.3.x contain a vulnerability that could allow an attacker to cause a system crash by running particular security scans.
Attacker Value
Unknown

CVE-2022-29089

Disclosure Date: September 01, 2022 (last updated October 08, 2023)
Dell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclosure vulnerability. A remote, unauthenticated attacker could potentially exploit this vulnerability by reverse engineering to retrieve sensitive information and access the REST API with admin privileges.
Attacker Value
Unknown

CVE-2022-27774

Disclosure Date: June 02, 2022 (last updated March 28, 2024)
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
Attacker Value
Unknown

CVE-2022-27775

Disclosure Date: June 02, 2022 (last updated March 28, 2024)
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.