Show filters
1,219 Total Results
Displaying 491-500 of 1,219
Sort by:
Attacker Value
Unknown

CVE-2022-34449

Disclosure Date: February 11, 2023 (last updated February 24, 2025)
PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the application.
Attacker Value
Unknown

CVE-2022-34448

Disclosure Date: February 11, 2023 (last updated February 24, 2025)
PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Cross-site Request Forgery vulnerability. An unauthenticated non-privileged user could potentially exploit the issue and perform any privileged state-changing actions.
Attacker Value
Unknown

CVE-2022-34447

Disclosure Date: February 11, 2023 (last updated February 24, 2025)
PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains OS Command Injection vulnerability. An authenticated remote attacker with administrative privileges could potentially exploit the issue and execute commands on the system as the root user.
Attacker Value
Unknown

CVE-2022-34446

Disclosure Date: February 11, 2023 (last updated February 24, 2025)
PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive information, and modify the configuration.
Attacker Value
Unknown

CVE-2022-34445

Disclosure Date: February 11, 2023 (last updated February 24, 2025)
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure.
Attacker Value
Unknown

CVE-2022-34444

Disclosure Date: February 11, 2023 (last updated February 24, 2025)
Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to cause data leak.
Attacker Value
Unknown

CVE-2022-34404

Disclosure Date: February 11, 2023 (last updated February 24, 2025)
Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service.
Attacker Value
Unknown

CVE-2022-34392

Disclosure Date: February 11, 2023 (last updated February 24, 2025)
SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.
Attacker Value
Unknown

CVE-2022-34389

Disclosure Date: February 11, 2023 (last updated February 24, 2025)
Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated attacker could potentially exploit this vulnerability and impersonate a legitimate dell customer to a dell support technician.
Attacker Value
Unknown

CVE-2022-34388

Disclosure Date: February 11, 2023 (last updated February 24, 2025)
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive information in the database of the affected application.