Dell
Dell Unity XT Operating Environment: vulnerabilidades y CVE
Dell Unity XT Operating Environment tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-22229 | Media (4.3) | 0.30% | — | 24 ene 2024 | Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and… |
| CVE-2023-43082 | Media (5.9) | 0.29% | — | 22 nov 2023 | Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by… |
| CVE-2023-43067 | Media (6.5) | 0.44% | — | 23 oct 2023 | Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploit this vulnerability disclosing local files in the file system. |
| CVE-2023-43066 | Alta (7.8) | 0.18% | — | 23 oct 2023 | Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local attacker to exploit this vulnerability by authenticating to the device CLI and issuing certain commands. |
| CVE-2023-43074 | Alta (7.5) | 0.47% | — | 23 oct 2023 | Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server. |
| CVE-2023-43065 | Media (5.4) | 0.29% | — | 23 oct 2023 | Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability. A low-privileged authenticated attacker can exploit these issues to obtain escalated privileges. |
| CVE-2022-29085 | Media (6.7) | 0.18% | — | 2 jun 2022 | Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high… |
| CVE-2022-29084 | Crítica (9.8) | 1.9% | — | 2 jun 2022 | Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability… |
| CVE-2022-29091 | Media (6.1) | 1.0% | — | 26 may 2022 | Dell Unity, Dell UnityVSA, and Dell UnityXT versions prior to 5.2.0.0.5.173 contain a Reflected Cross-Site Scripting Vulnerability in Unisphere GUI. An Unauthenticated Remote Attacker could potentially exploit this… |
| CVE-2021-21547 | Media (6.7) | 0.14% | — | 30 abr 2021 | Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerability when the Dell Upgrade Readiness Utility is run on the system. The credentials of the Unisphere… |
Otros productos de Dell
Secure Connect Gateway · 135Data Domain Operating System · 99Powerscale Onefs · 98EMC Powerscale Onefs · 84Wyse Management Suite · 70Latitude 9410 Firmware · 65Latitude 5411 Firmware · 64Latitude 5511 Firmware · 64Latitude 7410 Firmware · 63Latitude 7310 Firmware · 63Latitude 5310 Firmware · 62Latitude 5400 Firmware · 62