Vulnerabilidades em Dell EMC

97 resultados
Análise Vexday

Com 88 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, Dell EMC apresenta uma taxa de exploração abaixo da média geral do catálogo, o que indica pressão operacional imediata relativamente contida. No entanto, 13 vulnerabilidades possuem prova de conceito pública disponível, o que eleva o risco potencial de exploração futura, especialmente considerando que 4 delas são classificadas como críticas. A falha mais prevalente é do tipo CWE-321 (uso de chaves criptográficas fixas), padrão que tende a comprometer confidencialidade e autenticidade de forma ampla e sistêmica. A CVE mais perigosa ativa no momento é CVE-2018-1217, com score EPSS de 0,4664, sinalizando probabilidade relevante de exploração e merecendo atenção prioritária mesmo sem registro formal de exploração ativa.

CVE-2018-1204Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 iEPSS 1.8%CVE-2019-3737HIGHDell EMC Avamar Security Update for ADMe Web UI VulnerabilityEPSS 1.8%CVE-2018-1183In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8EPSS 1.8%CVE-2018-11062Dell EMC Integrated Data Protection Appliance Undocumented Accounts VulnerabilityEPSS 1.7%CVE-2018-1213Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 aEPSS 1.7%CVE-2018-1203In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 -EPSS 1.7%CVE-2018-11070MEDIUMRSA BSAFE Crypto-J versions prior to 6.2.4 and RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during EPSS 1.7%CVE-2017-14384In Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability. A rEPSS 1.6%CVE-2018-1238Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA). This component is uEPSS 1.6%CVE-2018-1250MEDIUMDell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user cEPSS 1.6%CVE-2016-9880The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authenticatioEPSS 1.6%CVE-2018-11059HIGHRSA Archer, versions prior to 6.4.0.1, contain a stored cross-site scripting vulnerability. A remote authenticated malicious Archer user couEPSS 1.6%CVE-2018-1205Dell EMC ScaleIO, versions prior to 2.5, do not properly handle some packet data in the MDM service. As a result, a remote attacker could poEPSS 1.5%CVE-2014-3626The Grails Resource Plugin often has to exchange URIs for resources with other internal components. Those other components will decode any UEPSS 1.5%CVE-2016-5685Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injectioEPSS 1.4%CVE-2018-1233RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-site scripting vulneraEPSS 1.4%CVE-2018-1237Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LEPSS 1.3%CVE-2018-11065LOWThe WorkPoint component, which is embedded in all RSA Archer, versions 6.1.x, 6.2.x, 6.3.x prior to 6.3.0.7 and 6.4.x prior to 6.4.0.1, contEPSS 1.3%CVE-2018-1246MEDIUMDell EMC Unity and UnityVSA contains reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploEPSS 1.3%CVE-2019-3754MEDIUMDell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe320EPSS 1.3%