Dell Powermax Os
By the Year
In 2024 there have been 0 vulnerabilities in Dell Powermax Os . Last year Powermax Os had 9 security vulnerabilities published. Right now, Powermax Os is on track to have less security vulnerabilities in 2024 than it did last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2024 | 0 | 0.00 |
2023 | 9 | 6.96 |
2022 | 3 | 7.93 |
2021 | 1 | 7.80 |
2020 | 1 | 8.10 |
2019 | 0 | 0.00 |
2018 | 0 | 0.00 |
It may take a day or so for new Powermax Os vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Dell Powermax Os Security Vulnerabilities
Dell vApp Manager, versions prior to 9.2.4.x contain an information disclosure vulnerability
CVE-2023-48671
7.5 - High
- December 14, 2023
Dell vApp Manager, versions prior to 9.2.4.x contain an information disclosure vulnerability. A remote attacker could potentially exploit this vulnerability leading to obtain sensitive information that may aid in further attacks.
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability
CVE-2023-48662
7.2 - High
- December 14, 2023
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
Shell injection
Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability
CVE-2023-48661
4.9 - Medium
- December 14, 2023
Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability to read arbitrary files from the target system.
Files or Directories Accessible to External Parties
Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability
CVE-2023-48660
7.5 - High
- December 14, 2023
Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote attacker could potentially exploit this vulnerability to read arbitrary files from the target system.
Directory traversal
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability
CVE-2023-48663
7.2 - High
- December 14, 2023
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
Shell injection
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability
CVE-2023-48665
7.2 - High
- December 14, 2023
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
Shell injection
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability
CVE-2023-48664
7.2 - High
- December 14, 2023
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
Shell injection
Dell EMC Unisphere for PowerMax versions before 9.1.0.27
CVE-2021-21548
7.4 - High
- March 17, 2023
Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victims data in transit.
Improper Certificate Validation
Dell Unisphere for PowerMax vApp
CVE-2022-45103
6.5 - Medium
- January 18, 2023
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system.
Information Disclosure
Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability
CVE-2022-31233
8 - High
- August 31, 2022
Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to.
Incorrect Resource Transfer Between Spheres
The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts
CVE-2021-36339
7.8 - High
- January 21, 2022
The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance.
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability
CVE-2021-36338
8 - High
- January 21, 2022
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.
Reliance on Cookies without Validation and Integrity Checking
Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability
CVE-2021-21531
7.8 - High
- April 30, 2021
Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.
Incorrect Resource Transfer Between Spheres
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17
CVE-2020-5367
8.1 - High
- June 23, 2020
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim's data in transit.
Improper Certificate Validation
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Dell Emc Unisphere Powermax Virtual Appliance or by Dell? Click the Watch button to subscribe.