Dell Unisphere For Powermax Virtual Appliance vulnerabilities

18 known vulnerabilities affecting dell/unisphere_for_powermax_virtual_appliance.

Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH16MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2025-36588HIGHCVSS 8.8fixed in 9.2.4.19≥ N/A, < 9.2.4.192026-01-22
CVE-2025-36588 [HIGH] CWE-89 CVE-2025-36588: Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special E Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
cvelistv5nvd
CVE-2025-36589HIGHCVSS 7.1≥ 9.2.4.17, < 9.2.4.192026-01-06
CVE-2025-36589 [HIGH] CWE-611 CVE-2025-36589: Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.
nvd
CVE-2025-36595HIGHCVSS 7.2≥ 9.2.4.0, < 9.2.4.172025-06-27
CVE-2025-36595 [HIGH] CWE-96 CVE-2025-36595: Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Direc Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2024-25946HIGHCVSS 8.8fixed in 9.2.4.92024-03-28
CVE-2024-25946 [HIGH] CWE-78 CVE-2024-25946: Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorize Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.
nvd
CVE-2024-25955HIGHCVSS 8.8fixed in 9.2.4.92024-03-28
CVE-2024-25955 [HIGH] CWE-78 CVE-2024-25955: Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorize Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.
nvd
CVE-2023-48664HIGHCVSS 7.2fixed in 9.2.4.72023-12-14
CVE-2023-48664 [HIGH] CWE-78 CVE-2023-48664: Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote ma Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
nvd
CVE-2023-48671HIGHCVSS 7.5fixed in 9.2.4.72023-12-14
CVE-2023-48671 [HIGH] CWE-200 CVE-2023-48671: Dell vApp Manager, versions prior to 9.2.4.x contain an information disclosure vulnerability. A rem Dell vApp Manager, versions prior to 9.2.4.x contain an information disclosure vulnerability. A remote attacker could potentially exploit this vulnerability leading to obtain sensitive information that may aid in further attacks.
nvd
CVE-2023-48665HIGHCVSS 7.2fixed in 9.2.4.72023-12-14
CVE-2023-48665 [HIGH] CWE-78 CVE-2023-48665: Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote ma Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
nvd
CVE-2023-48662HIGHCVSS 7.2fixed in 9.2.4.72023-12-14
CVE-2023-48662 [HIGH] CWE-78 CVE-2023-48662: Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote ma Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
nvd
CVE-2023-48660HIGHCVSS 7.5fixed in 9.2.4.72023-12-14
CVE-2023-48660 [HIGH] CWE-22 CVE-2023-48660: Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote attacker could potentially exploit this vulnerability to read arbitrary files from the target system.
nvd
CVE-2023-48663HIGHCVSS 7.2fixed in 9.2.4.72023-12-14
CVE-2023-48663 [HIGH] CWE-78 CVE-2023-48663: Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote ma Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
nvd
CVE-2023-48661MEDIUMCVSS 4.9fixed in 9.2.4.72023-12-14
CVE-2023-48661 [MEDIUM] CWE-552 CVE-2023-48661: Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability to read arbitrary files from the target system.
nvd
CVE-2022-34397MEDIUMCVSS 5.7fixed in 9.2.3.22fixed in 9.2.4.262023-02-13
CVE-2022-34397 [MEDIUM] CWE-863 CVE-2022-34397: Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 an Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.
nvd
CVE-2022-45104HIGHCVSS 8.8fixed in 9.2.4.262023-02-11
CVE-2022-45104 [HIGH] CWE-77 CVE-2022-45104: Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x con Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands on the underlying system.
nvd
CVE-2022-31233HIGHCVSS 8.0fixed in 9.2.3.152022-08-31
CVE-2022-31233 [HIGH] CWE-602 CVE-2022-31233: Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adj Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to.
nvd
CVE-2021-36338HIGHCVSS 8.0fixed in 9.1.0.31≥ 9.2.0.0, < 9.2.3.42022-01-21
CVE-2021-36338 [HIGH] CWE-602 CVE-2021-36338: Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An a Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.
nvd
CVE-2021-36339HIGHCVSS 7.8fixed in 9.1.0.31≥ 9.2.0.0, < 9.2.3.42022-01-21
CVE-2021-36339 [HIGH] CWE-250 CVE-2021-36339: The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance.
nvd
CVE-2021-21531HIGHCVSS 7.8fixed in 9.1.0.26≥ 9.2.1.0, < 9.2.1.62021-04-30
CVE-2021-21531 [HIGH] CWE-602 CVE-2021-21531: Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.
nvd