PatchSiren

Dell CVE debriefs · Page 5

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Dell CVE published 2026-08-19

CVE-2026-58565

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T15:17:13.280Z and has not been modified since then. Dell Command Update (DCU) versions prior to 5.7.1 contain a Missing Authorization vulnerability, tracked as CVE-2026-58565, with a CVSS score of 8.8. A low-privileged attacker with local access could potentially exploit this vulnerability, leadi [truncated]

HIGH Dell CVE published 2026-08-19

CVE-2026-58564

Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access. This issue was published on 2026-08-19T15:17:12.980Z and has not been modified since then. The CVE record indicates that users of Dell Command Update versions prior to 5.7.1 should [truncated]

HIGH Dell CVE published 2026-08-19

CVE-2026-58562

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T15:17:12.603Z and has not been modified since then. Dell Command Update (DCU) versions prior to 5.7.1 contain a Missing Authorization vulnerability, classified as CWE-862. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. Thi [truncated]

HIGH Dell CVE published 2026-08-19

CVE-2026-56797

A low-privileged attacker with local access could potentially exploit the Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Dell Command Update (DCU), versions prior to 5.7.1, leading to Elevation of Privileges. This vulnerability exists due to a timing issue in the update process, allowing an attacker to manipulate the update mechanism. To mitigate this risk, it is essential to review th [truncated]

MEDIUM Dell CVE published 2026-08-19

CVE-2026-56796

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T15:17:11.800Z and has not been modified since then. CVE-2026-56796 is an Improper Link Resolution Before File Access ('Link Following') vulnerability in Dell Command Update (DCU) versions prior to 5.7.1. A low privileged attacker with local access could exploit this vulnerability to elevate privi [truncated]

MEDIUM Dell CVE published 2026-08-19

CVE-2026-54793

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. This vulnerability affects IT administrators and security teams responsible for Dell OpenManage Enterprise systems, esp [truncated]

HIGH Dell CVE published 2026-08-19

CVE-2026-49817

Dell Command Update (DCU) versions prior to 5.7.1 are affected by a Deserialization of Untrusted Data vulnerability, which could lead to Elevation of Privileges. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The CVE record was published on 2026-08-19T15:17:07.480Z and has not been modified since then. Organizations should review their deployments and plan for updates to mi [truncated]

MEDIUM Dell CVE published 2026-08-19

CVE-2026-70424

Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Path Traversal vulnerability. A low-privileged attacker with remote access could exploit this, leading to information exposure. The CVE-2026-70424 record was published on 2026-08-19T14:17:39.190Z. Evidence is limited to public sources and may not reflect the full scope or impact. Defenders should verify affected systems, review vendor guidanc [truncated]

MEDIUM Dell CVE published 2026-08-19

CVE-2026-70423

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. The affected product is Dell OpenManage Enterprise. This vulnerability is classified as an Improper Restriction of XML External Entity Reference. The [truncated]

HIGH Dell CVE published 2026-08-19

CVE-2026-70422

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an SQL injection vulnerability. A low-privileged attacker with remote access could potentially exploit this vulnerability, leading to script injection. The affected product or component is Dell OpenManage Enterprise, and the vulnerability class is SQL injection. The likely operational impact is script injection, and the source-confidence limits [truncated]

HIGH Dell CVE published 2026-08-19

CVE-2026-70421

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. This issue affects IT administrators and security teams responsible for Dell OpenManage Enterprise systems, especially those with remote access configurations. The vulner [truncated]

HIGH Dell CVE published 2026-08-19

CVE-2026-54796

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This vulnerability affects Dell OpenManage Enterprise installations, particularly those with remote access and high [truncated]

HIGH Dell CVE published 2026-08-19

CVE-2026-54794

Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. This vulnerability has a CVSS score of 7.2 and is classified as HIGH severity. The CVE record was published on 2026-08-19T14:17:34.040Z and has not been modified since [truncated]

HIGH Dell CVE published 2026-08-18

CVE-2026-70415

Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution and denial of service. The vulnerability is tracked as CVE-2026-70415 and has a CVSS score of 8.1. Organizations using Dell PowerStore SDNAS should prioritize patching and review compe [truncated]

HIGH Dell CVE published 2026-08-14

CVE-2026-66270

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-14T16:16:58.913Z and has not been modified since then. Dell Wyse Management Suite (WMS) versions prior to 2605.0.2 contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote C [truncated]

MEDIUM Dell CVE published 2026-08-14

CVE-2026-63702

Dell Wyse Management Suite (WMS) versions prior to 2605.0.2 contain a Use of Hard-coded Credentials vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. This vulnerability was published on 2026-08-14 and has not been modified since then. Administrators and users of Dell Wyse Management Suite (WMS) versions prior to 2605.0. [truncated]

MEDIUM Dell CVE published 2026-08-14

CVE-2026-63701

Dell Wyse Management Suite (WMS) versions prior to 2605.0.2 are vulnerable to Improper Deserialization of Untrusted Data. A low-privileged attacker with local access could exploit this, leading to Privilege Escalation. The vulnerability affects Dell Wyse Management Suite installations. Security teams should review the official advisory for accurate risk assessment and mitigation strategies, focusing on lo [truncated]

CRITICAL Dell CVE published 2026-08-06

CVE-2026-67261

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:24.430Z and has not been modified since then. Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, are affected by an OS Command Injection vulnerability in the IAPI component. This critical vulnerability allows an unauthenticated remote attacker to achieve [truncated]

CRITICAL Dell CVE published 2026-08-06

CVE-2026-54489

Dell Virtual Storage Integrator for VMware vSphere Client versions prior to 10.11.1.0 contain a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fu [truncated]

HIGH Dell CVE published 2026-08-03

CVE-2026-59913

Dell Display and Peripheral Manager (DDPM Mac) versions prior to 2.3.0.1005 contain a Missing Authentication for Critical Function vulnerability, allowing low-privileged attackers with local access to potentially elevate privileges. Organizations should apply patches or updates to version 2.3.0.1005 or later, restrict local access to sensitive systems, and monitor for suspicious activity. The vulnerabilit [truncated]

HIGH Dell CVE published 2026-08-03

CVE-2026-59912

Dell Display and Peripheral Manager (DDPM Mac) versions prior to 2.3.0.1005 contain an Improper Access Control vulnerability. A low-privileged attacker with local access could exploit this, leading to elevation of privileges and arbitrary code execution. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Users should prioritize patching to prevent potential elevation of privileg [truncated]

HIGH Dell CVE published 2026-07-22

CVE-2026-49499

CVE-2026-49499 is a Generation of Incorrect Security Tokens vulnerability in Dell PowerProtect Data Manager's IAM. A low-privileged attacker with remote access could exploit this, leading to privilege escalation. The vulnerability exists in the Identity and Access Management (IAM) component of Dell PowerProtect Data Manager. Successful exploitation could allow a low-privileged attacker with remote access [truncated]

CRITICAL Dell CVE published 2026-07-22

CVE-2026-46738

CVE-2026-46738 is a CRITICAL 9.1 vulnerability in Dell PowerProtect Data Manager, a data management solution. A high privileged attacker with remote access could potentially exploit this Improper Input Validation vulnerability in the REST API, leading to Elevation of privileges. This vulnerability affects versions prior to 20.2.0.0. Security teams should review and validate affected scope, severity, and v [truncated]

MEDIUM Dell CVE published 2026-07-22

CVE-2026-46737

CVE-2026-46737 is an Improper Input Validation vulnerability in the REST API of Dell PowerProtect Data Manager versions prior to 20.2.0.0. A high-privileged attacker with remote access could exploit this vulnerability, potentially leading to remote code execution. The vulnerability exists due to inadequate validation of input in the REST API, which could allow an attacker to execute arbitrary code. Admini [truncated]

MEDIUM Dell CVE published 2026-07-22

CVE-2026-44276

A high privileged attacker with local access could potentially exploit this vulnerability in Dell PowerProtect Data Manager, versions prior to 20.2.0.0, leading to Information exposure via the REST API. This vulnerability is classified as an Exposure of Sensitive Information to an Unauthorized Actor. The CVE record and NVD entry provide additional context for this vulnerability.

CRITICAL Dell CVE published 2026-07-22

CVE-2026-40712

CVE-2026-40712 is a CRITICAL 9.1 vulnerability in Dell PowerProtect Data Manager's REST API, allowing high-privileged attackers with remote access to potentially exploit an Improper Input Validation vulnerability, leading to privilege escalation. This vulnerability affects versions prior to 20.2.0.0. Security teams must prioritize patching to prevent potential attacks.

HIGH Dell CVE published 2026-07-15

CVE-2026-56687

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T18:16:48.493Z and has not been modified since then. This Obsolete Feature in UI vulnerability affects Dell ThinOS 10, versions prior to 2605_10.2100. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. Security teams should rev [truncated]

MEDIUM Dell CVE published 2026-07-15

CVE-2026-49501

CVE-2026-49501 is an Improper Privilege Management vulnerability affecting Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7 and 9.11.0.0 through 9.13.0.2. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability has a CVSS score of 6.7 and a severity of MEDIUM. System administrators and security teams should be [truncated]

MEDIUM Dell CVE published 2026-07-10

CVE-2026-54470

CVE-2026-54470 is an Improper Restriction of XML External Entity Reference vulnerability in Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Security teams should review the CVE record and NVD entry for fu [truncated]

HIGH Dell CVE published 2026-07-10

CVE-2026-54469

A low privileged attacker with remote access could potentially exploit the Deserialization of Untrusted Data vulnerability in Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, leading to arbitrary command execution with root privileges. This executive overview covers the affected product, vulnerability class, and likely operational impact. The vulnerability has a CVSS score of 8.8 and a severity of HIGH.