Dell Powermax Os vulnerabilities

16 known vulnerabilities affecting dell/powermax_os.

Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH12MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2023-48664HIGHCVSS 7.2v59782023-12-14
CVE-2023-48664 [HIGH] CWE-78 CVE-2023-48664: Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote ma Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
nvd
CVE-2023-48671HIGHCVSS 7.5v59782023-12-14
CVE-2023-48671 [HIGH] CWE-200 CVE-2023-48671: Dell vApp Manager, versions prior to 9.2.4.x contain an information disclosure vulnerability. A rem Dell vApp Manager, versions prior to 9.2.4.x contain an information disclosure vulnerability. A remote attacker could potentially exploit this vulnerability leading to obtain sensitive information that may aid in further attacks.
nvd
CVE-2023-48665HIGHCVSS 7.2v59782023-12-14
CVE-2023-48665 [HIGH] CWE-78 CVE-2023-48665: Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote ma Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
nvd
CVE-2023-48662HIGHCVSS 7.2v59782023-12-14
CVE-2023-48662 [HIGH] CWE-78 CVE-2023-48662: Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote ma Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
nvd
CVE-2023-48660HIGHCVSS 7.5v59782023-12-14
CVE-2023-48660 [HIGH] CWE-22 CVE-2023-48660: Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote attacker could potentially exploit this vulnerability to read arbitrary files from the target system.
nvd
CVE-2023-48663HIGHCVSS 7.2v59782023-12-14
CVE-2023-48663 [HIGH] CWE-78 CVE-2023-48663: Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote ma Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
nvd
CVE-2023-48661MEDIUMCVSS 4.9v59782023-12-14
CVE-2023-48661 [MEDIUM] CWE-552 CVE-2023-48661: Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability to read arbitrary files from the target system.
nvd
CVE-2021-21548HIGHCVSS 7.4v59782023-03-17
CVE-2021-21548 [HIGH] CWE-295 CVE-2021-21548: Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual A Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a
nvd
CVE-2022-45103MEDIUMCVSS 6.5v59782023-01-18
CVE-2022-45103 [MEDIUM] CWE-200 CVE-2022-45103: Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x con Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system.
nvd
CVE-2022-31233HIGHCVSS 8.0v59782022-08-31
CVE-2022-31233 [HIGH] CWE-602 CVE-2022-31233: Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adj Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to.
nvd
CVE-2021-36338HIGHCVSS 8.0v59782022-01-21
CVE-2021-36338 [HIGH] CWE-602 CVE-2021-36338: Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An a Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.
nvd
CVE-2021-36339HIGHCVSS 7.8v59782022-01-21
CVE-2021-36339 [HIGH] CWE-250 CVE-2021-36339: The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance.
nvd
CVE-2021-21531HIGHCVSS 7.8v59782021-04-30
CVE-2021-21531 [HIGH] CWE-602 CVE-2021-21531: Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.
nvd
CVE-2020-35170MEDIUMCVSS 5.4v5978.221.221v5978.479.4792021-01-05
CVE-2020-35170 [MEDIUM] CWE-79 CVE-2020-35170: Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject javascript code and affect other authentic
nvd
CVE-2020-5367HIGHCVSS 8.1v59782020-06-23
CVE-2020-5367 [HIGH] CWE-295 CVE-2020-5367: Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying
nvd
CVE-2020-5345MEDIUMCVSS 5.4v59782020-06-23
CVE-2020-5345 [MEDIUM] CWE-602 CVE-2020-5345: Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability. An authenticated malicious user may potentially execute commands to alter or stop database statistics.
nvd