Dell
Dell Update Package Framework: vulnerabilidades y CVE
Dell Update Package Framework tiene 10 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses6
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86358 | Alta (8.8) | 0.41% | — | 16 sept 2026 | Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability,… |
| CVE-2026-71182 | Media (6) | 0.15% | — | 16 sept 2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit… |
| CVE-2026-71181 | Media (6) | 0.15% | — | 16 sept 2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit… |
| CVE-2026-71180 | Alta (7.8) | 0.15% | — | 16 sept 2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation… |
| CVE-2026-71179 | Alta (7.8) | 0.59% | — | 16 sept 2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local… |
| CVE-2026-23857 | Alta (8.2) | 0.10% | — | 12 feb 2026 | Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could… |
| CVE-2025-22395 | Alta (7.8) | 0.19% | — | 7 ene 2025 | Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of… |
| CVE-2023-39254 | Alta (7.3) | 0.17% | — | 1 mar 2024 | Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code… |
| CVE-2023-32454 | Alta (7.1) | 0.17% | — | 6 feb 2024 | DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to… |
| CVE-2019-3726 | Media (6.7) | 0.46% | — | 24 sept 2019 | An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and Framework file versions prior to 103.4.6.69 used in Dell EMC Servers.… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Dell
Secure Connect Gateway · 135Data Domain Operating System · 99Powerscale Onefs · 98EMC Powerscale Onefs · 84Wyse Management Suite · 70Latitude 9410 Firmware · 65Latitude 5411 Firmware · 64Latitude 5511 Firmware · 64Latitude 7410 Firmware · 63Latitude 7310 Firmware · 63Latitude 5310 Firmware · 62Latitude 5400 Firmware · 62