Latest CVE Feed
-
6.7
MEDIUMCVE-2021-21595
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts Smartlock WORM compliance mode clus... Read more
- EPSS Score: %0.19
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-21594
Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerability. It can lead to potential disclosure of sensitive data. Dell recommends upgrading at your earliest opportunity.... Read more
- EPSS Score: %0.26
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21592
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged user could potentially exploit this vulnerability, leading to unauthorized information disclosure.... Read more
- EPSS Score: %0.22
- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-21591
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user... Read more
- EPSS Score: %0.12
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-21590
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user... Read more
- EPSS Score: %0.12
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-21589
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not exit on failed Initialization. A local authenticated Service user could potentially exploit this vulnerability to escalate privileges.... Read more
- EPSS Score: %0.04
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21588
Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Prese... Read more
Affected Products : powerflex_presentation_server- EPSS Score: %0.14
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-21587
Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A local unauthenticated attacker could exploit this vulnerability in order to obtain the path of files and folders.... Read more
Affected Products : wyse_management_suite- EPSS Score: %5.40
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-21586
Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated malicious user could exploit this vulnerability in order to read arbitrary files on the system.... Read more
Affected Products : wyse_management_suite- EPSS Score: %46.07
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-21585
Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tools. A remote authenticated malicious user with high privileges may potentially exploit this vulnerability to execute arbitrary OS comman... Read more
Affected Products : openmanage_enterprise- EPSS Score: %1.37
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-21584
Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability. An authenticated low privileged attacker may potentially exploit this vulnerability leading to disclosure of the OIDC... Read more
- EPSS Score: %0.24
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21581
Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a spec... Read more
Affected Products : emc_idrac9_firmware- EPSS Score: %0.25
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21580
Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into bel... Read more
- EPSS Score: %0.48
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-21579
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted link... Read more
Affected Products : emc_idrac9_firmware- EPSS Score: %0.53
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-21578
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted link... Read more
Affected Products : emc_idrac9_firmware- EPSS Score: %0.52
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-21577
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to follow... Read more
Affected Products : emc_idrac9_firmware- EPSS Score: %0.27
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-21576
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to follow... Read more
Affected Products : emc_idrac9_firmware- EPSS Score: %0.27
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21575
Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability. ... Read more
Affected Products : bsafe_micro-edition-suite- EPSS Score: %0.09
- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21574
Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.... Read more
- EPSS Score: %0.09
- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21573
Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.... Read more
- EPSS Score: %0.05
- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024