Show filters
1,219 Total Results
Displaying 421-430 of 1,219
Sort by:
Attacker Value
Unknown

CVE-2023-25936

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
Attacker Value
Unknown

CVE-2023-32464

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim’s data in transit.
Attacker Value
Unknown

CVE-2023-32463

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
Dell VxRail, version(s) 8.0.100 and earlier contain a denial-of-service vulnerability in the upgrade functionality. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to degraded performance and system malfunction.
Attacker Value
Unknown

CVE-2023-32449

Disclosure Date: June 22, 2023 (last updated February 25, 2025)
Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks
Attacker Value
Unknown

CVE-2023-32465

Disclosure Date: June 14, 2023 (last updated February 25, 2025)
Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability. An attacker could potentially exploit this vulnerability, leading to unauthorized admin access to the Cyber Recovery application. Exploitation may lead to complete system takeover by an attacker.
Attacker Value
Unknown

CVE-2023-28066

Disclosure Date: June 01, 2023 (last updated February 25, 2025)
Dell OS Recovery Tool, versions 2.2.4013 and 2.3.7012.0, contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability in order to elevate privileges on the system.
Attacker Value
Unknown

CVE-2023-28043

Disclosure Date: June 01, 2023 (last updated February 25, 2025)
Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerability to retrieve the plain text.
Attacker Value
Unknown

CVE-2023-25539

Disclosure Date: May 31, 2023 (last updated February 25, 2025)
Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. This is a high severity vulnerability as the exploitation allows an attacker to take complete control of a system, so Dell recommends customers to upgrade at the earliest opportunity.
Attacker Value
Unknown

CVE-2023-32448

Disclosure Date: May 30, 2023 (last updated February 25, 2025)
PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains License Key Stored in Cleartext vulnerability. A local user with access to the installation directory can retrieve the license key of the product and use it to install and license PowerPath on different systems.
Attacker Value
Unknown

CVE-2023-28080

Disclosure Date: May 30, 2023 (last updated February 25, 2025)
PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains DLL Hijacking Vulnerabilities. A regular user (non-admin) can exploit these issues to potentially escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM.