PatchSiren

Dell CVE debriefs · Page 8

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Dell CVE published 2026-05-22

CVE-2025-32745

CVE-2025-32745 describes an Improper Certificate Validation vulnerability within Dell PowerFlex Manager versions less than or equal to 4.6.2. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to information tampering. The CVSS score for this vulnerability is 4.2, indicating a medium severity level. The vulnerability exists due to improper certif [truncated]

MEDIUM Dell CVE published 2026-05-22

CVE-2025-26483

CVE-2025-26483 is an Open Redirect Vulnerability in Dell PowerFlex Manager, versions 4.6.2 and prior. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information. This vulnerability has a [truncated]

HIGH Dell CVE published 2026-05-20

CVE-2025-32750

Published on 2026-05-20, CVE-2025-32750 affects Dell PowerFlex Manager versions 4.6.2 and earlier. NVD rates the issue HIGH with a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating an unauthenticated remote attacker could potentially expose information through directory listing.

MEDIUM Dell CVE published 2026-05-20

CVE-2026-35070

CVE-2026-35070 describes a command injection weakness in Dell SmartFabric Storage Software before version 1.4.5. According to the CVE description and NVD metadata, exploitation requires local access with high privileges, but could still lead to filesystem access for the attacker. NVD currently lists the record as awaiting analysis, so organizations should treat vendor/product details as tied to the Dell a [truncated]

MEDIUM Dell CVE published 2026-05-18

CVE-2026-41119

A medium-severity vulnerability in Dell Live Optics collectors allows remote unauthenticated attackers to bypass SSL/TLS certificate validation, potentially enabling man-in-the-middle attacks that compromise data confidentiality and integrity. The vulnerability stems from improper certificate validation (CWE-295) in both Windows and Personal Edition collector software. Dell has published security advisory [truncated]

MEDIUM Dell CVE published 2026-04-20

CVE-2026-35154

CVE-2026-35154 is a Dell PowerProtect Data Domain vulnerability involving improper privilege management. According to the CVE description, a high-privileged attacker with local access could potentially elevate privileges to perform unauthorized delete operations. The issue was publicly disclosed on 2026-04-20 and later modified on 2026-05-11. The NVD record lists CVSS 3.1 severity as MEDIUM (6.3) with loc [truncated]

MEDIUM Dell CVE published 2026-04-17

CVE-2026-35074

Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading [truncated]

MEDIUM Dell CVE published 2026-04-17

CVE-2026-35073

CVE-2026-35073 is an improper neutralization of special elements used in an OS command injection vulnerability in Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60. A high privileged attacker with local access could potentially exploit this vulnerabil [truncated]

MEDIUM Dell CVE published 2026-04-17

CVE-2026-35072

Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0 are affected by an OS command injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. This CVE record was published on 2026-04-17T11:16:10.090Z and has not been modified since then. The vu [truncated]

HIGH Dell CVE published 2026-04-08

CVE-2026-28261

CVE-2026-28261 is an Insertion of Sensitive Information into Log File vulnerability affecting Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0. A low privileged attacker with local access could potentially exploit this vulnerability, leading to secret exposure. The vulnerability has a CVSS score of 7.8 and is classified as HIGH seve [truncated]

MEDIUM Dell CVE published 2026-04-08

CVE-2026-27102

CVE-2026-27102 is an incorrect privilege assignment vulnerability affecting Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.6 and 9.11.0.0 through 9.13.0.1. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. This vulnerability has a medium severity level, with a CVSS score of 6.6, and requires attention from system administra [truncated]

MEDIUM Dell CVE published 2026-04-08

CVE-2026-24511

CVE-2026-24511: Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.6 and 9.11.0.0 through 9.13.0.0 contain a generation of error message containing sensitive information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. The vulnerability exists in the Dell PowerScale OneFS versions, allowing an attacker to access [truncated]

MEDIUM Dell CVE published 2026-04-01

CVE-2026-28265

A low-privileged attacker with local access could potentially exploit the Path Traversal vulnerability in Dell PowerStore, leading to modification of arbitrary system files. This vulnerability, tracked as CVE-2026-28265, has a CVSS score of 4.4 and a Medium severity rating. The vulnerability allows an attacker to modify system files, potentially leading to unauthorized system modifications. System adminis [truncated]

Known exploited Dell CVE published 2026-02-18

CVE-2026-22769

CVE-2026-22769 affects Dell RecoverPoint for Virtual Machines (RP4VMs) and is described as a use of hard-coded credentials vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-02-18 with a due date of 2026-02-21, so defenders should treat it as an urgent remediation item. The supplied corpus directs organizations to apply Dell’s mitigations, follow applicable CISA BOD 22-01 [truncated]

Known exploited Dell CVE published 2022-03-31

CVE-2021-21551

CVE-2021-21551 is a Dell dbutil Driver insufficient access control vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-31, which makes it a high-priority remediation item for defenders. Use Dell’s update guidance and verify affected systems are patched or otherwise remediated.

CRITICAL Dell CVE published 2017-02-22

CVE-2016-9684

CVE-2016-9684 is a critical network-reachable command injection issue in the SonicWall Secure Remote Access web administrative interface. The affected viewcert CGI component (/cgi-bin/viewcert) fails to properly escape the CERT value before calling system(), which can allow remote command execution. The supplied description notes that successful exploitation can yield shell access as the nobody user.

CRITICAL Dell CVE published 2017-02-22

CVE-2016-9683

CVE-2016-9683 is a critical command injection flaw in the SonicWall Secure Remote Access server web administrative interface. The vulnerable CGI component can pass an unsanitized script filename into system(), which can let a remote attacker run commands and obtain a shell as the nobody user. Public CVE disclosure is dated 2017-02-22.

CRITICAL Dell CVE published 2017-02-22

CVE-2016-9682

CVE-2016-9682 describes two remote command injection flaws in the SonicWall Secure Remote Access server web administrative interface. The issue is in the diagnostics CGI at /cgi-bin/diagnostics, where attacker-controlled values are passed to system() without proper escaping. NVD classifies the flaw as CWE-77 and assigns a CVSS v3.0 score of 9.8, reflecting network reachability, no authentication, no user [truncated]

HIGH Dell CVE published 2017-02-21

CVE-2015-4057

CVE-2015-4057 is an information-disclosure issue in the Plug-in for VMware vCenter in Dell VCE Vision Intelligent Operations before 2.6.5. When a user requests the Settings screen, the product sends a cleartext HTTP response, which can allow a network observer to recover the admin user password. NVD rates the issue HIGH with a 7.5 CVSS score, reflecting unauthenticated network exposure and confidentiality [truncated]

MEDIUM Dell CVE published 2017-02-21

CVE-2015-4056

CVE-2015-4056 describes weak cryptography in the System Library of VCE Vision Intelligent Operations before 2.6.5. According to the official vulnerability record, a local user with administrative access could leverage the flaw to discover credentials. The issue was publicly disclosed in the CVE/NVD record on 2017-02-21 and is categorized by NVD as CWE-310.

LOW Dell CVE published 2017-02-03

CVE-2016-8217

CVE-2016-8217 describes a timing-side-channel weakness in EMC RSA BSAFE Crypto-J PKCS#12 handling. The issue affects versions prior to 6.2.2 and arises because the toolkit compares a stored MAC with a calculated MAC using a non-constant-time method. NVD rates the issue LOW with CVSS 3.1 vector AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N.

MEDIUM Dell CVE published 2017-02-03

CVE-2016-8216

CVE-2016-8216 is a command injection vulnerability in Dell EMC Data Domain OS. NVD rates it 6.7 (medium) and the published advisory scope covers Data Domain OS 5.4 all versions, plus 5.5, 5.6, and 5.7 families before the fixed releases. Because the CVSS vector includes local access and high privileges, the issue is most relevant where administrative or otherwise privileged access is possible.

HIGH Dell CVE published 2017-02-03

CVE-2016-8212

CVE-2016-8212 is a high-severity certificate-validation flaw in EMC RSA BSAFE Crypto-J versions prior to 6.2.2. The issue affects OCSP response handling: when a response omits nextUpdate, Crypto-J may treat that response as valid indefinitely instead of limiting acceptance to a short window around thisUpdate. That weakens revocation checking for affected deployments and is similar to CVE-2015-4748.

HIGH Dell CVE published 2017-02-03

CVE-2016-8211

CVE-2016-8211 is a high-severity path traversal issue affecting EMC Data Protection Advisor versions 6.1.x, 6.2, 6.2.1, 6.2.2, and 6.2.3 before patch 446. The NVD record classifies it as CWE-22 and assigns a CVSS 3.1 score of 7.5, indicating a network-reachable issue with no privileges or user interaction required and high confidentiality impact. Organizations running the affected product should treat thi [truncated]