Show filters
60 Total Results
Displaying 31-40 of 60
Sort by:
Attacker Value
Unknown

CVE-2022-34434

Disclosure Date: September 15, 2022 (last updated October 08, 2023)
Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the Postgres database. A threat actor with root level access to either the vApp or containerized versions of Cloud Mobility may potentially exploit this vulnerability, leading to the modification or deletion of tables that are required for many of the core functionalities of Cloud Mobility. Exploitation may lead to the compromise of integrity and availability of the normal functionality of the Cloud Mobility application.
Attacker Value
Unknown

CVE-2022-33936

Disclosure Date: July 06, 2022 (last updated October 07, 2023)
Cloud Mobility for Dell EMC Storage, 1.3.0.XXX contains a RCE vulnerability. A non-privileged user could potentially exploit this vulnerability, leading to achieving a root shell. This is a critical issue; so Dell recommends customers to upgrade at the earliest opportunity.
Attacker Value
Unknown

CVE-2022-26856

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application's database with privileges of the compromised account.
Attacker Value
Unknown

CVE-2021-36302

Disclosure Date: September 01, 2021 (last updated February 23, 2025)
All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A remote malicious user with standard level JEA credentials may potentially exploit this vulnerability to elevate privileges and take over the system.
Attacker Value
Unknown

CVE-2021-21505

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges.
Attacker Value
Unknown

CVE-2021-21517

Disclosure Date: February 25, 2021 (last updated February 22, 2025)
SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.
Attacker Value
Unknown

CVE-2020-5389

Disclosure Date: October 05, 2020 (last updated February 22, 2025)
Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an information disclosure vulnerability. Authenticated low privileged OMIMSCC users may be able to retrieve sensitive information from the logs.
Attacker Value
Unknown

CVE-2020-5320

Disclosure Date: January 22, 2020 (last updated February 23, 2025)
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a SQL injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions.
Attacker Value
Unknown

CVE-2020-5323

Disclosure Date: January 22, 2020 (last updated February 23, 2025)
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an injection vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to gain access to sensitive information or cause denial-of-service.
Attacker Value
Unknown

CVE-2020-5321

Disclosure Date: January 22, 2020 (last updated February 23, 2025)
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an improper input validation vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to spawn tasks with elevated privileges.