Dell Vulnerabilities and Affected Products
Vulnerabilities associated with Dell OpenManage Enterprise.
Products
Clear product- PowerScale OneFS173 vulnerabilities
- CPG BIOS110 vulnerabilities
- Unity61 vulnerabilities
- Wyse Management Suite53 vulnerabilities
- PowerProtect Data Domain49 vulnerabilities
- PowerEdge Platform33 vulnerabilities
- SmartFabric OS10 Software28 vulnerabilities
- PowerProtect DD25 vulnerabilities
- Integrated Dell Remote Access Controller (iDRAC)24 vulnerabilities
- PowerProtect Data Manager23 vulnerabilities
- PowerStore23 vulnerabilities
- PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS202322 vulnerabilities
- PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS202421 vulnerabilities
- CloudLink20 vulnerabilities
- Unisphere for PowerMax19 vulnerabilities
- PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release18 vulnerabilities
- powerscale_onefs18 vulnerabilities
- NetWorker16 vulnerabilities
- ECS15 vulnerabilities
- PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS202515 vulnerabilities
- Avamar14 vulnerabilities
- Alienware Command Center (AWCC)13 vulnerabilities
- ControlVault313 vulnerabilities
- ControlVault3 Plus13 vulnerabilities
- Dell OpenManage Enterprise13 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-45767MEDIUM | Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. CWE-89Oct 17, 2024 | CVSS4.3v3.1 | EPSS0.316% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-45766HIGH | Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. CWE-94Oct 17, 2024 | CVSS8.0v3.1 | EPSS0.546% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-28979MEDIUM | Dell OpenManage Enterprise, versions 4.1.0 and older, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. | CVSS5.1v3.1 | EPSS0.257% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-28978MEDIUM | Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability. A high privileged remote attacker could potentially exploit this vulnerability, leading to unauthorized access to resources. CWE-284May 1, 2024 | CVSS5.2v3.1 | EPSS0.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-28961MEDIUM | Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to obtain credentials leading to unauthorized access with elevated privileges. This could lead to further attacks, thus Dell recommends customers to upgrade at the earliest opportunity. | CVSS6.3v3.1 | EPSS0.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-25944MEDIUM | Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to the files stored on the server filesystem, with the privileges of the running web application. | CVSS5.7v3.1 | EPSS0.765% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-21596CRITICAL | Dell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remote code execution vulnerability. A malicious attacker with access to the immediate subnet may potentially exploit this vulnerability leading to information disclosure and a possible elevation of privileges. CWE-200Aug 9, 2021 | CVSS9.6v3.1 | EPSS0.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-21585CRITICAL | Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tools. A remote authenticated malicious user with high privileges may potentially exploit this vulnerability to execute arbitrary OS commands. CWE-78Aug 9, 2021 | CVSS9.1v3.1 | EPSS2.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-21584HIGH | Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability. An authenticated low privileged attacker may potentially exploit this vulnerability leading to disclosure of the OIDC server credentials. CWE-200Aug 9, 2021 | CVSS7.7v3.1 | EPSS0.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-21564CRITICAL | Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to hijack an elevated session or perform unauthorized actions by sending malformed data. | CVSS9.8v3.1 | EPSS1.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-5323MEDIUM | Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an injection vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to gain access to sensitive information or cause denial-of-service. | CVSS5.4v3.1 | EPSS1.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-5321HIGH | Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an improper input validation vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to spawn tasks with elevated privileges. CWE-20Jul 19, 2021 | CVSS7.6v3.1 | EPSS0.938% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-5320CRITICAL | Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a SQL injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions. CWE-89Jul 19, 2021 | CVSS9.0v3.1 | EPSS0.929% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |