Vulnerabilidades em Dell EMC

97 resultados
Análise Vexday

Com 88 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, Dell EMC apresenta uma taxa de exploração abaixo da média geral do catálogo, o que indica pressão operacional imediata relativamente contida. No entanto, 13 vulnerabilidades possuem prova de conceito pública disponível, o que eleva o risco potencial de exploração futura, especialmente considerando que 4 delas são classificadas como críticas. A falha mais prevalente é do tipo CWE-321 (uso de chaves criptográficas fixas), padrão que tende a comprometer confidencialidade e autenticidade de forma ampla e sistêmica. A CVE mais perigosa ativa no momento é CVE-2018-1217, com score EPSS de 0,4664, sinalizando probabilidade relevante de exploração e merecendo atenção prioritária mesmo sem registro formal de exploração ativa.

CVE-2018-1202Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and version 7.1.1.11 is affected by a cross-siEPSS 2.9%CVE-2018-1239Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injection vulnerabilities. EPSS 2.8%CVE-2018-1211Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI parser which could be uEPSS 2.6%CVE-2019-3721MEDIUMImproper Range Header Processing VulnerabilityEPSS 2.6%CVE-2018-1242Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contains a command injection vulnerabilityEPSS 2.5%CVE-2018-1201Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affeEPSS 2.5%CVE-2018-1188Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and versions 7.2.1.x is affected by a cross-siEPSS 2.5%CVE-2018-1251HIGHDell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker cEPSS 2.5%CVE-2018-1187Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6 is affected by a cross-site scripting vulnerabiEPSS 2.4%CVE-2018-1186Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affeEPSS 2.4%CVE-2018-11067Dell EMC Avamar and Integrated Data Protection Appliance Open Redirection VulnerabilityEPSS 2.4%CVE-2018-1232RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow EPSS 2.2%CVE-2018-11048Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 conEPSS 2.1%CVE-2019-3708HIGHCross-Site Scripting Vulnerability in OVA file upload featureEPSS 2.1%CVE-2019-3709HIGHCross-Site Scripting Vulnerability while registering vCenter serversEPSS 2.1%CVE-2019-3723CRITICALWeb Parameter Tampering VulnerabilityEPSS 1.8%CVE-2018-11071HIGHDSA-2018-147: Dell EMC Isilon OneFS and IsilonSD Edge Remote Process Crash VulnerabilityEPSS 1.8%CVE-2018-1248RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host headEPSS 1.8%CVE-2018-1243HIGHiDRAC6/iDRAC7/iDRAC8 - Weak CGI session ID vulnerabilityEPSS 1.8%CVE-2017-8013EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and vaEPSS 1.8%