Vulnerabilidades em Dell EMC

97 resultados
Análise Vexday

Com 88 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, Dell EMC apresenta uma taxa de exploração abaixo da média geral do catálogo, o que indica pressão operacional imediata relativamente contida. No entanto, 13 vulnerabilidades possuem prova de conceito pública disponível, o que eleva o risco potencial de exploração futura, especialmente considerando que 4 delas são classificadas como críticas. A falha mais prevalente é do tipo CWE-321 (uso de chaves criptográficas fixas), padrão que tende a comprometer confidencialidade e autenticidade de forma ampla e sistêmica. A CVE mais perigosa ativa no momento é CVE-2018-1217, com score EPSS de 0,4664, sinalizando probabilidade relevante de exploração e merecendo atenção prioritária mesmo sem registro formal de exploração ativa.

CVE-2018-11060HIGHRSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious ArcheEPSS 3.0%CVE-2018-1199Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 anEPSS 2.9%CVE-2018-1242Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contains a command injection vulnerabilityEPSS 2.7%CVE-2018-1232RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow EPSS 2.7%CVE-2019-3721MEDIUMImproper Range Header Processing VulnerabilityEPSS 2.6%CVE-2018-1251HIGHDell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker cEPSS 2.5%CVE-2018-1204Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 iEPSS 2.4%CVE-2019-3708HIGHCross-Site Scripting Vulnerability in OVA file upload featureEPSS 2.2%CVE-2019-3709HIGHCross-Site Scripting Vulnerability while registering vCenter serversEPSS 2.2%CVE-2017-8013EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and vaEPSS 2.2%CVE-2018-1202Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and version 7.1.1.11 is affected by a cross-siEPSS 2.2%CVE-2018-1203In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 -EPSS 2.1%CVE-2018-1183In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8EPSS 2.1%CVE-2018-11048Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 conEPSS 2.1%CVE-2016-9880The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authenticatioEPSS 2.1%CVE-2018-1213Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 aEPSS 2.0%CVE-2018-1201Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affeEPSS 1.9%CVE-2018-1188Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and versions 7.2.1.x is affected by a cross-siEPSS 1.9%CVE-2019-3723CRITICALWeb Parameter Tampering VulnerabilityEPSS 1.8%CVE-2018-11071HIGHDSA-2018-147: Dell EMC Isilon OneFS and IsilonSD Edge Remote Process Crash VulnerabilityEPSS 1.8%