RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_ssl-j | 3.0 |
| cisco | icdn | 2.0 |
| dell | bsafe_ssl-j | 3.1 |
| dell | bsafe_ssl-j | 3.0.1 |
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.9 | 3.6 |
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-476,CWE-476,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| hp | wbem | a.01.05.08 |
| stonesoft | stonegate | 2.0.5 |
| cisco | pix_firewall_software | 6.1 |
| vmware | gsx_server | 3.0_build_7592 |
| securecomputing | sidewinder | 5.2.1.02 |
| stonesoft | stonegate | 2.2.1 |
| lite | speed_technologies_litespeed_web_server | 1.3_rc3 |
| novell | edirectory | 8.5.27 |
| avaya | sg203 | 4.31.29 |
| vmware | gsx_server | 2.5.1 |
| stonesoft | stonegate | 2.2.4 |
| avaya | s8500 | r2.0.0 |
| cisco | ios | 12.2(14)sy1 |
| vmware | gsx_server | 2.0.1_build_2129 |
| stonesoft | stonegate | 2.0.4 |
| cisco | application_and_content_networking_software | * |
| avaya | sg5 | 4.4 |
| cisco | firewall_services_module | 1.1_(3.005) |
| neoteris | instant_virtual_extranet | 3.1 |
| freebsd | freebsd | 5.2.1 |
| stonesoft | stonebeat_fullcluster | 3.0 |
| cisco | webns | 7.10 |
| cisco | okena_stormwatch | 3.2 |
| stonesoft | stonegate | 1.6.3 |
| cisco | ios | 12.1(11b)e |
| sgi | propack | 2.3 |
| cisco | content_services_switch_11500 | * |
| cisco | webns | 6.10_b4 |
| stonesoft | stonegate_vpn_client | 2.0.9 |
| 4d | webstar | 5.2.3 |
| openssl | openssl | 0.9.6k |
| avaya | vsu | 100_r2.0.1 |
| redhat | openssl | 0.9.6b-3 |
| cisco | pix_firewall_software | 6.2(3) |
| cisco | pix_firewall_software | 6.0(3) |
| redhat | linux | 7.2 |
| avaya | s8700 | r2.0.1 |
| cisco | webns | 7.2_0.0.03 |
| checkpoint | firewall-1 | next_generation_fp0 |
| avaya | s8300 | r2.0.0 |
| openssl | openssl | 0.9.6f |
| 4d | webstar | 5.3.1 |
| cisco | secure_content_accelerator | 10000 |
| cisco | pix_firewall_software | 6.3 |
| stonesoft | stonebeat_fullcluster | 1_2.0 |
| novell | edirectory | 8.5 |
| 4d | webstar | 5.2 |
| tarantella | tarantella_enterprise | 3.40 |
| cisco | pix_firewall_software | 6.3(2) |
| bluecoat | cacheos_ca_sa | 4.1.10 |
| cisco | mds_9000 | * |
| securecomputing | sidewinder | 5.2.0.02 |
| cisco | ios | 12.1(11b)e12 |
| stonesoft | stonegate | 1.5.18 |
| 4d | webstar | 5.2.1 |
| cisco | pix_firewall_software | 6.2(1) |
| symantec | clientless_vpn_gateway_4400 | 5.0 |
| cisco | webns | 7.1_0.2.06 |
| stonesoft | servercluster | 2.5.2 |
| cisco | webns | 7.1_0.1.02 |
| redhat | openssl | 0.9.7a-2 |
| lite | speed_technologies_litespeed_web_server | 1.0.2 |
| cisco | css11000_content_services_switch | * |
| avaya | s8500 | r2.0.1 |
| stonesoft | stonebeat_fullcluster | 1_3.0 |
| lite | speed_technologies_litespeed_web_server | 1.2.2 |
| novell | edirectory | 8.6.2 |
| avaya | sg208 | 4.4 |
| hp | hp-ux | 8.05 |
| 4d | webstar | 5.2.2 |
| stonesoft | stonegate | 2.0.8 |
| cisco | pix_firewall_software | 6.0(1) |
| redhat | linux | 8.0 |
| checkpoint | firewall-1 | 2.0 |
| openssl | openssl | 0.9.7 |
| openssl | openssl | 0.9.6e |
| hp | hp-ux | 11.23 |
| cisco | pix_firewall_software | 6.3(3.109) |
| cisco | access_registrar | * |
| novell | edirectory | 8.7 |
| neoteris | instant_virtual_extranet | 3.0 |
| lite | speed_technologies_litespeed_web_server | 1.3_rc2 |
| hp | hp-ux | 11.11 |
| stonesoft | stonegate_vpn_client | 2.0 |
| freebsd | freebsd | 4.9 |
| checkpoint | firewall-1 | * |
| hp | apache-based_web_server | 2.0.43.04 |
| neoteris | instant_virtual_extranet | 3.3.1 |
| lite | speed_technologies_litespeed_web_server | 1.0.1 |
| apple | mac_os_x | 10.3.3 |
| cisco | pix_firewall_software | 6.0(2) |
| avaya | converged_communications_server | 2.0 |
| avaya | sg200 | 4.31.29 |
| cisco | ios | 12.1(11b)e14 |
| cisco | pix_firewall_software | 6.0(4.101) |
| cisco | ios | 12.1(13)e9 |
| freebsd | freebsd | 5.1 |
| avaya | s8700 | r2.0.0 |
| checkpoint | firewall-1 | next_generation_fp2 |
| openbsd | openbsd | 3.4 |
| sgi | propack | 3.0 |
| sgi | propack | 2.4 |
| avaya | vsu | 7500_r2.0.1 |
| stonesoft | stonebeat_fullcluster | 2.5 |
| lite | speed_technologies_litespeed_web_server | 1.3_rc1 |
| openssl | openssl | 0.9.7c |
| stonesoft | stonegate | 1.5.17 |
| cisco | ios | 12.2(14)sy |
| avaya | vsu | 10000_r2.0.1 |
| stonesoft | stonegate | 1.7 |
| stonesoft | stonegate | 1.7.2 |
| cisco | firewall_services_module | 2.1_(0.208) |
| openssl | openssl | 0.9.6j |
| tarantella | tarantella_enterprise | 3.20 |
| vmware | gsx_server | 2.5.1_build_5336 |
| stonesoft | stonebeat_securitycluster | 2.5 |
| 4d | webstar | 5.2.4 |
| sco | openserver | 5.0.6 |
| avaya | vsu | 5 |
| cisco | pix_firewall | 6.2.2_.111 |
| hp | wbem | a.02.00.00 |
| stonesoft | servercluster | 2.5 |
| bluecoat | cacheos_ca_sa | 4.1.12 |
| stonesoft | stonebeat_fullcluster | 2.0 |
| stonesoft | stonegate_vpn_client | 1.7 |
| avaya | vsu | 2000_r2.0.1 |
| stonesoft | stonegate | 1.7.1 |
| bluecoat | proxysg | * |
| avaya | sg5 | 4.3 |
| freebsd | freebsd | 4.8 |
| openssl | openssl | 0.9.7a |
| cisco | pix_firewall_software | 6.1(4) |
| lite | speed_technologies_litespeed_web_server | 1.1.1 |
| vmware | gsx_server | 2.0 |
| cisco | css_secure_content_accelerator | 2.0 |
| avaya | intuity_audix | 5.1.46 |
| securecomputing | sidewinder | 5.2.0.01 |
| cisco | threat_response | * |
| hp | wbem | a.02.00.01 |
| cisco | firewall_services_module | 1.1.2 |
| stonesoft | stonegate | 2.0.1 |
| stonesoft | stonegate | 2.0.7 |
| stonesoft | stonegate_vpn_client | 1.7.2 |
| neoteris | instant_virtual_extranet | 3.2 |
| redhat | openssl | 0.9.6-15 |
| freebsd | freebsd | 5.2 |
| lite | speed_technologies_litespeed_web_server | 1.1 |
| stonesoft | stonegate | 2.1 |
| novell | edirectory | 8.5.12a |
| avaya | sg208 | * |
| lite | speed_technologies_litespeed_web_server | 1.2_rc1 |
| cisco | call_manager | * |
| cisco | pix_firewall_software | 6.2 |
| cisco | ios | 12.2za |
| avaya | sg203 | 4.4 |
| stonesoft | stonebeat_securitycluster | 2.0 |
| avaya | intuity_audix | s3400 |
| stonesoft | stonegate | 2.0.9 |
| cisco | ciscoworks_common_services | 2.2 |
| avaya | s8300 | r2.0.1 |
| checkpoint | provider-1 | 4.1 |
| sco | openserver | 5.0.7 |
| hp | hp-ux | 11.00 |
| securecomputing | sidewinder | 5.2.0.04 |
| lite | speed_technologies_litespeed_web_server | 1.3 |
| sun | crypto_accelerator_4000 | 1.0 |
| stonesoft | stonegate | 2.2 |
| cisco | ios | 12.1(11)e |
| openbsd | openbsd | 3.3 |
| cisco | pix_firewall_software | 6.2(2) |
| cisco | pix_firewall_software | 6.3(1) |
| tarantella | tarantella_enterprise | 3.30 |
| dell | bsafe_ssl-j | 3.1 |
| openssl | openssl | 0.9.6c |
| cisco | ios | 12.1(19)e1 |
| cisco | pix_firewall_software | 6.0(4) |
| cisco | webns | 7.10_.0.06s |
| lite | speed_technologies_litespeed_web_server | 1.3.1 |
| neoteris | instant_virtual_extranet | 3.3 |
| lite | speed_technologies_litespeed_web_server | 1.2_rc2 |
| 4d | webstar | 4.0 |
| stonesoft | stonegate_vpn_client | 2.0.8 |
| cisco | pix_firewall_software | 6.1(1) |
| checkpoint | vpn-1 | next_generation_fp2 |
| cisco | ios | 12.2sy |
| cisco | pix_firewall_software | 6.0 |
| avaya | vsu | 5000_r2.0.1 |
| openssl | openssl | 0.9.7b |
| cisco | pix_firewall_software | 6.2(3.100) |
| openssl | openssl | 0.9.6h |
| hp | apache-based_web_server | 2.0.43.00 |
| cisco | webns | 6.10 |
| avaya | vsu | 5x |
| openssl | openssl | 0.9.6g |
| dell | bsafe_ssl-j | 3.0 |
| lite | speed_technologies_litespeed_web_server | 1.0.3 |
| cisco | css_secure_content_accelerator | 1.0 |
| securecomputing | sidewinder | 5.2 |
| checkpoint | vpn-1 | vsx_ng_with_application_intelligence |
| dell | bsafe_ssl-j | 3.0.1 |
| cisco | pix_firewall_software | 6.1(2) |
| avaya | intuity_audix | s3210 |
| novell | imanager | 1.5 |
| openssl | openssl | 0.9.6i |
| novell | edirectory | 8.7.1 |
| openssl | openssl | 0.9.6d |
| securecomputing | sidewinder | 5.2.1 |
| novell | edirectory | 8.0 |
| cisco | gss_4480_global_site_selector | * |
| cisco | pix_firewall_software | 6.1(3) |
| redhat | enterprise_linux | 3.0 |
| avaya | intuity_audix | * |
| stonesoft | stonegate_vpn_client | 2.0.7 |
| checkpoint | firewall-1 | next_generation_fp1 |
| avaya | vsu | 500 |
| stonesoft | stonegate | 1.6.2 |
| redhat | linux | 7.3 |
| cisco | ciscoworks_common_management_foundation | 2.1 |
| checkpoint | vpn-1 | next_generation_fp0 |
| lite | speed_technologies_litespeed_web_server | 1.2.1 |
| cisco | pix_firewall_software | 6.3(3.102) |
| securecomputing | sidewinder | 5.2.0.03 |
| stonesoft | stonegate | 2.0.6 |
| checkpoint | vpn-1 | next_generation_fp1 |
| hp | aaa_server | * |
| cisco | firewall_services_module | * |
| 4d | webstar | 5.3 |
| avaya | sg5 | 4.2 |
| cisco | firewall_services_module | 1.1.3 |
| cisco | gss_4490_global_site_selector | * |
| novell | imanager | 2.0 |
| cisco | pix_firewall_software | 6.1(5) |
| apple | mac_os_x_server | 10.3.3 |
| stonesoft | stonebeat_webcluster | 2.5 |
| stonesoft | stonebeat_webcluster | 2.0 |
| redhat | enterprise_linux_desktop | 3.0 |
| avaya | sg200 | 4.4 |
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| hp | wbem | a.01.05.08 |
| stonesoft | stonegate | 2.0.5 |
| cisco | pix_firewall_software | 6.1 |
| vmware | gsx_server | 3.0_build_7592 |
| securecomputing | sidewinder | 5.2.1.02 |
| stonesoft | stonegate | 2.2.1 |
| lite | speed_technologies_litespeed_web_server | 1.3_rc3 |
| novell | edirectory | 8.5.27 |
| avaya | sg203 | 4.31.29 |
| vmware | gsx_server | 2.5.1 |
| stonesoft | stonegate | 2.2.4 |
| avaya | s8500 | r2.0.0 |
| cisco | ios | 12.2(14)sy1 |
| vmware | gsx_server | 2.0.1_build_2129 |
| stonesoft | stonegate | 2.0.4 |
| cisco | application_and_content_networking_software | * |
| avaya | sg5 | 4.4 |
| cisco | firewall_services_module | 1.1_(3.005) |
| neoteris | instant_virtual_extranet | 3.1 |
| freebsd | freebsd | 5.2.1 |
| stonesoft | stonebeat_fullcluster | 3.0 |
| cisco | webns | 7.10 |
| cisco | okena_stormwatch | 3.2 |
| stonesoft | stonegate | 1.6.3 |
| cisco | ios | 12.1(11b)e |
| sgi | propack | 2.3 |
| cisco | content_services_switch_11500 | * |
| cisco | webns | 6.10_b4 |
| stonesoft | stonegate_vpn_client | 2.0.9 |
| 4d | webstar | 5.2.3 |
| openssl | openssl | 0.9.6k |
| avaya | vsu | 100_r2.0.1 |
| redhat | openssl | 0.9.6b-3 |
| cisco | pix_firewall_software | 6.2(3) |
| cisco | pix_firewall_software | 6.0(3) |
| redhat | linux | 7.2 |
| avaya | s8700 | r2.0.1 |
| cisco | webns | 7.2_0.0.03 |
| checkpoint | firewall-1 | next_generation_fp0 |
| avaya | s8300 | r2.0.0 |
| openssl | openssl | 0.9.6f |
| 4d | webstar | 5.3.1 |
| cisco | secure_content_accelerator | 10000 |
| cisco | pix_firewall_software | 6.3 |
| stonesoft | stonebeat_fullcluster | 1_2.0 |
| novell | edirectory | 8.5 |
| 4d | webstar | 5.2 |
| tarantella | tarantella_enterprise | 3.40 |
| cisco | pix_firewall_software | 6.3(2) |
| bluecoat | cacheos_ca_sa | 4.1.10 |
| cisco | mds_9000 | * |
| securecomputing | sidewinder | 5.2.0.02 |
| cisco | ios | 12.1(11b)e12 |
| stonesoft | stonegate | 1.5.18 |
| 4d | webstar | 5.2.1 |
| cisco | pix_firewall_software | 6.2(1) |
| symantec | clientless_vpn_gateway_4400 | 5.0 |
| cisco | webns | 7.1_0.2.06 |
| stonesoft | servercluster | 2.5.2 |
| cisco | webns | 7.1_0.1.02 |
| redhat | openssl | 0.9.7a-2 |
| lite | speed_technologies_litespeed_web_server | 1.0.2 |
| cisco | css11000_content_services_switch | * |
| avaya | s8500 | r2.0.1 |
| stonesoft | stonebeat_fullcluster | 1_3.0 |
| lite | speed_technologies_litespeed_web_server | 1.2.2 |
| novell | edirectory | 8.6.2 |
| avaya | sg208 | 4.4 |
| hp | hp-ux | 8.05 |
| 4d | webstar | 5.2.2 |
| stonesoft | stonegate | 2.0.8 |
| cisco | pix_firewall_software | 6.0(1) |
| redhat | linux | 8.0 |
| checkpoint | firewall-1 | 2.0 |
| openssl | openssl | 0.9.7 |
| openssl | openssl | 0.9.6e |
| hp | hp-ux | 11.23 |
| cisco | pix_firewall_software | 6.3(3.109) |
| cisco | access_registrar | * |
| novell | edirectory | 8.7 |
| neoteris | instant_virtual_extranet | 3.0 |
| lite | speed_technologies_litespeed_web_server | 1.3_rc2 |
| hp | hp-ux | 11.11 |
| stonesoft | stonegate_vpn_client | 2.0 |
| freebsd | freebsd | 4.9 |
| checkpoint | firewall-1 | * |
| hp | apache-based_web_server | 2.0.43.04 |
| neoteris | instant_virtual_extranet | 3.3.1 |
| lite | speed_technologies_litespeed_web_server | 1.0.1 |
| apple | mac_os_x | 10.3.3 |
| cisco | pix_firewall_software | 6.0(2) |
| avaya | converged_communications_server | 2.0 |
| avaya | sg200 | 4.31.29 |
| cisco | ios | 12.1(11b)e14 |
| cisco | pix_firewall_software | 6.0(4.101) |
| cisco | ios | 12.1(13)e9 |
| freebsd | freebsd | 5.1 |
| checkpoint | vpn-1 | next_generation |
| avaya | s8700 | r2.0.0 |
| checkpoint | firewall-1 | next_generation_fp2 |
| openbsd | openbsd | 3.4 |
| sgi | propack | 3.0 |
| sgi | propack | 2.4 |
| avaya | vsu | 7500_r2.0.1 |
| stonesoft | stonebeat_fullcluster | 2.5 |
| lite | speed_technologies_litespeed_web_server | 1.3_rc1 |
| openssl | openssl | 0.9.7c |
| stonesoft | stonegate | 1.5.17 |
| cisco | ios | 12.2(14)sy |
| avaya | vsu | 10000_r2.0.1 |
| stonesoft | stonegate | 1.7 |
| stonesoft | stonegate | 1.7.2 |
| cisco | firewall_services_module | 2.1_(0.208) |
| openssl | openssl | 0.9.6j |
| tarantella | tarantella_enterprise | 3.20 |
| vmware | gsx_server | 2.5.1_build_5336 |
| stonesoft | stonebeat_securitycluster | 2.5 |
| 4d | webstar | 5.2.4 |
| sco | openserver | 5.0.6 |
| avaya | vsu | 5 |
| cisco | pix_firewall | 6.2.2_.111 |
| hp | wbem | a.02.00.00 |
| stonesoft | servercluster | 2.5 |
| bluecoat | cacheos_ca_sa | 4.1.12 |
| stonesoft | stonebeat_fullcluster | 2.0 |
| stonesoft | stonegate_vpn_client | 1.7 |
| avaya | vsu | 2000_r2.0.1 |
| stonesoft | stonegate | 1.7.1 |
| bluecoat | proxysg | * |
| avaya | sg5 | 4.3 |
| freebsd | freebsd | 4.8 |
| openssl | openssl | 0.9.7a |
| cisco | pix_firewall_software | 6.1(4) |
| lite | speed_technologies_litespeed_web_server | 1.1.1 |
| vmware | gsx_server | 2.0 |
| cisco | css_secure_content_accelerator | 2.0 |
| avaya | intuity_audix | 5.1.46 |
| securecomputing | sidewinder | 5.2.0.01 |
| cisco | threat_response | * |
| hp | wbem | a.02.00.01 |
| cisco | firewall_services_module | 1.1.2 |
| stonesoft | stonegate | 2.0.1 |
| stonesoft | stonegate | 2.0.7 |
| stonesoft | stonegate_vpn_client | 1.7.2 |
| neoteris | instant_virtual_extranet | 3.2 |
| redhat | openssl | 0.9.6-15 |
| freebsd | freebsd | 5.2 |
| lite | speed_technologies_litespeed_web_server | 1.1 |
| stonesoft | stonegate | 2.1 |
| novell | edirectory | 8.5.12a |
| avaya | sg208 | * |
| lite | speed_technologies_litespeed_web_server | 1.2_rc1 |
| cisco | call_manager | * |
| cisco | pix_firewall_software | 6.2 |
| cisco | ios | 12.2za |
| avaya | sg203 | 4.4 |
| stonesoft | stonebeat_securitycluster | 2.0 |
| avaya | intuity_audix | s3400 |
| stonesoft | stonegate | 2.0.9 |
| cisco | ciscoworks_common_services | 2.2 |
| avaya | s8300 | r2.0.1 |
| checkpoint | provider-1 | 4.1 |
| sco | openserver | 5.0.7 |
| hp | hp-ux | 11.00 |
| securecomputing | sidewinder | 5.2.0.04 |
| lite | speed_technologies_litespeed_web_server | 1.3 |
| sun | crypto_accelerator_4000 | 1.0 |
| stonesoft | stonegate | 2.2 |
| cisco | ios | 12.1(11)e |
| openbsd | openbsd | 3.3 |
| cisco | pix_firewall_software | 6.2(2) |
| cisco | pix_firewall_software | 6.3(1) |
| tarantella | tarantella_enterprise | 3.30 |
| dell | bsafe_ssl-j | 3.1 |
| openssl | openssl | 0.9.6c |
| cisco | ios | 12.1(19)e1 |
| cisco | pix_firewall_software | 6.0(4) |
| cisco | webns | 7.10_.0.06s |
| lite | speed_technologies_litespeed_web_server | 1.3.1 |
| neoteris | instant_virtual_extranet | 3.3 |
| lite | speed_technologies_litespeed_web_server | 1.2_rc2 |
| 4d | webstar | 4.0 |
| stonesoft | stonegate_vpn_client | 2.0.8 |
| cisco | pix_firewall_software | 6.1(1) |
| cisco | ios | 12.2sy |
| cisco | pix_firewall_software | 6.0 |
| avaya | vsu | 5000_r2.0.1 |
| openssl | openssl | 0.9.7b |
| cisco | pix_firewall_software | 6.2(3.100) |
| openssl | openssl | 0.9.6h |
| hp | apache-based_web_server | 2.0.43.00 |
| cisco | webns | 6.10 |
| avaya | vsu | 5x |
| openssl | openssl | 0.9.6g |
| dell | bsafe_ssl-j | 3.0 |
| lite | speed_technologies_litespeed_web_server | 1.0.3 |
| cisco | css_secure_content_accelerator | 1.0 |
| securecomputing | sidewinder | 5.2 |
| checkpoint | vpn-1 | vsx_ng_with_application_intelligence |
| dell | bsafe_ssl-j | 3.0.1 |
| cisco | pix_firewall_software | 6.1(2) |
| avaya | intuity_audix | s3210 |
| novell | imanager | 1.5 |
| openssl | openssl | 0.9.6i |
| novell | edirectory | 8.7.1 |
| openssl | openssl | 0.9.6d |
| securecomputing | sidewinder | 5.2.1 |
| novell | edirectory | 8.0 |
| cisco | gss_4480_global_site_selector | * |
| cisco | pix_firewall_software | 6.1(3) |
| redhat | enterprise_linux | 3.0 |
| avaya | intuity_audix | * |
| stonesoft | stonegate_vpn_client | 2.0.7 |
| checkpoint | firewall-1 | next_generation_fp1 |
| avaya | vsu | 500 |
| stonesoft | stonegate | 1.6.2 |
| redhat | linux | 7.3 |
| cisco | ciscoworks_common_management_foundation | 2.1 |
| checkpoint | vpn-1 | next_generation_fp0 |
| lite | speed_technologies_litespeed_web_server | 1.2.1 |
| cisco | pix_firewall_software | 6.3(3.102) |
| securecomputing | sidewinder | 5.2.0.03 |
| stonesoft | stonegate | 2.0.6 |
| checkpoint | vpn-1 | next_generation_fp1 |
| hp | aaa_server | * |
| cisco | firewall_services_module | * |
| 4d | webstar | 5.3 |
| avaya | sg5 | 4.2 |
| cisco | firewall_services_module | 1.1.3 |
| cisco | gss_4490_global_site_selector | * |
| novell | imanager | 2.0 |
| cisco | pix_firewall_software | 6.1(5) |
| apple | mac_os_x_server | 10.3.3 |
| stonesoft | stonebeat_webcluster | 2.5 |
| stonesoft | stonebeat_webcluster | 2.0 |
| redhat | enterprise_linux_desktop | 3.0 |
| avaya | sg200 | 4.4 |
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-125,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| hp | wbem | a.01.05.08 |
| cisco | pix_firewall_software | 6.1 |
| vmware | gsx_server | 3.0_build_7592 |
| securecomputing | sidewinder | 5.2.1.02 |
| forcepoint | stonegate | 2.1 |
| novell | edirectory | 8.5.27 |
| avaya | sg203 | 4.31.29 |
| vmware | gsx_server | 2.5.1 |
| avaya | s8500 | r2.0.0 |
| cisco | ios | 12.2(14)sy1 |
| vmware | gsx_server | 2.0.1_build_2129 |
| cisco | application_and_content_networking_software | * |
| avaya | sg5 | 4.4 |
| cisco | firewall_services_module | 1.1_(3.005) |
| forcepoint | stonegate | 2.0.7 |
| neoteris | instant_virtual_extranet | 3.1 |
| freebsd | freebsd | 5.2.1 |
| stonesoft | stonebeat_fullcluster | 3.0 |
| cisco | webns | 7.10 |
| cisco | okena_stormwatch | 3.2 |
| cisco | ios | 12.1(11b)e |
| sgi | propack | 2.3 |
| forcepoint | stonegate | 1.7.2 |
| cisco | content_services_switch_11500 | * |
| forcepoint | stonegate | 2.0.8 |
| cisco | webns | 6.10_b4 |
| 4d | webstar | 5.2.3 |
| openssl | openssl | 0.9.6k |
| avaya | vsu | 100_r2.0.1 |
| redhat | openssl | 0.9.6b-3 |
| cisco | pix_firewall_software | 6.2(3) |
| cisco | pix_firewall_software | 6.0(3) |
| redhat | linux | 7.2 |
| avaya | s8700 | r2.0.1 |
| litespeedtech | litespeed_web_server | 1.0.1 |
| cisco | webns | 7.2_0.0.03 |
| checkpoint | firewall-1 | next_generation_fp0 |
| avaya | s8300 | r2.0.0 |
| openssl | openssl | 0.9.6f |
| 4d | webstar | 5.3.1 |
| cisco | secure_content_accelerator | 10000 |
| cisco | pix_firewall_software | 6.3 |
| stonesoft | stonebeat_fullcluster | 1_2.0 |
| novell | edirectory | 8.5 |
| 4d | webstar | 5.2 |
| tarantella | tarantella_enterprise | 3.40 |
| cisco | pix_firewall_software | 6.3(2) |
| bluecoat | cacheos_ca_sa | 4.1.10 |
| cisco | mds_9000 | * |
| securecomputing | sidewinder | 5.2.0.02 |
| forcepoint | stonegate | 2.0.1 |
| cisco | ios | 12.1(11b)e12 |
| 4d | webstar | 5.2.1 |
| forcepoint | stonegate | 1.7.1 |
| cisco | pix_firewall_software | 6.2(1) |
| symantec | clientless_vpn_gateway_4400 | 5.0 |
| cisco | webns | 7.1_0.2.06 |
| stonesoft | servercluster | 2.5.2 |
| cisco | webns | 7.1_0.1.02 |
| redhat | openssl | 0.9.7a-2 |
| forcepoint | stonegate | 1.7 |
| cisco | css11000_content_services_switch | * |
| avaya | s8500 | r2.0.1 |
| stonesoft | stonebeat_fullcluster | 1_3.0 |
| novell | edirectory | 8.6.2 |
| avaya | sg208 | 4.4 |
| hp | hp-ux | 8.05 |
| 4d | webstar | 5.2.2 |
| cisco | pix_firewall_software | 6.0(1) |
| redhat | linux | 8.0 |
| checkpoint | firewall-1 | 2.0 |
| openssl | openssl | 0.9.7 |
| openssl | openssl | 0.9.6e |
| hp | hp-ux | 11.23 |
| cisco | pix_firewall_software | 6.3(3.109) |
| cisco | access_registrar | * |
| novell | edirectory | 8.7 |
| neoteris | instant_virtual_extranet | 3.0 |
| hp | hp-ux | 11.11 |
| freebsd | freebsd | 4.9 |
| checkpoint | firewall-1 | * |
| forcepoint | stonegate | 2.0.4 |
| hp | apache-based_web_server | 2.0.43.04 |
| neoteris | instant_virtual_extranet | 3.3.1 |
| apple | mac_os_x | 10.3.3 |
| cisco | pix_firewall_software | 6.0(2) |
| avaya | converged_communications_server | 2.0 |
| avaya | sg200 | 4.31.29 |
| cisco | ios | 12.1(11b)e14 |
| cisco | pix_firewall_software | 6.0(4.101) |
| cisco | ios | 12.1(13)e9 |
| freebsd | freebsd | 5.1 |
| avaya | s8700 | r2.0.0 |
| checkpoint | firewall-1 | next_generation_fp2 |
| openbsd | openbsd | 3.4 |
| sgi | propack | 3.0 |
| sgi | propack | 2.4 |
| avaya | vsu | 7500_r2.0.1 |
| stonesoft | stonebeat_fullcluster | 2.5 |
| openssl | openssl | 0.9.7c |
| forcepoint | stonegate | 2.0.5 |
| cisco | ios | 12.2(14)sy |
| avaya | vsu | 10000_r2.0.1 |
| cisco | firewall_services_module | 2.1_(0.208) |
| openssl | openssl | 0.9.6j |
| tarantella | tarantella_enterprise | 3.20 |
| vmware | gsx_server | 2.5.1_build_5336 |
| stonesoft | stonebeat_securitycluster | 2.5 |
| 4d | webstar | 5.2.4 |
| sco | openserver | 5.0.6 |
| avaya | vsu | 5 |
| cisco | pix_firewall | 6.2.2_.111 |
| hp | wbem | a.02.00.00 |
| stonesoft | servercluster | 2.5 |
| bluecoat | cacheos_ca_sa | 4.1.12 |
| stonesoft | stonebeat_fullcluster | 2.0 |
| avaya | vsu | 2000_r2.0.1 |
| bluecoat | proxysg | * |
| avaya | sg5 | 4.3 |
| freebsd | freebsd | 4.8 |
| openssl | openssl | 0.9.7a |
| cisco | pix_firewall_software | 6.1(4) |
| vmware | gsx_server | 2.0 |
| cisco | css_secure_content_accelerator | 2.0 |
| avaya | intuity_audix | 5.1.46 |
| securecomputing | sidewinder | 5.2.0.01 |
| cisco | threat_response | * |
| hp | wbem | a.02.00.01 |
| cisco | firewall_services_module | 1.1.2 |
| forcepoint | stonegate | 1.5.18 |
| neoteris | instant_virtual_extranet | 3.2 |
| redhat | openssl | 0.9.6-15 |
| freebsd | freebsd | 5.2 |
| novell | edirectory | 8.5.12a |
| forcepoint | stonegate | 2.0.6 |
| avaya | sg208 | * |
| cisco | call_manager | * |
| cisco | pix_firewall_software | 6.2 |
| cisco | ios | 12.2za |
| avaya | sg203 | 4.4 |
| stonesoft | stonebeat_securitycluster | 2.0 |
| avaya | intuity_audix | s3400 |
| forcepoint | stonegate | 2.2 |
| forcepoint | stonegate | 1.6.3 |
| cisco | ciscoworks_common_services | 2.2 |
| forcepoint | stonegate | 1.6.2 |
| avaya | s8300 | r2.0.1 |
| checkpoint | provider-1 | 4.1 |
| sco | openserver | 5.0.7 |
| hp | hp-ux | 11.00 |
| securecomputing | sidewinder | 5.2.0.04 |
| forcepoint | stonegate | 2.2.4 |
| sun | crypto_accelerator_4000 | 1.0 |
| cisco | ios | 12.1(11)e |
| openbsd | openbsd | 3.3 |
| cisco | pix_firewall_software | 6.2(2) |
| cisco | pix_firewall_software | 6.3(1) |
| tarantella | tarantella_enterprise | 3.30 |
| forcepoint | stonegate | 1.5.17 |
| dell | bsafe_ssl-j | 3.1 |
| openssl | openssl | 0.9.6c |
| cisco | ios | 12.1(19)e1 |
| cisco | pix_firewall_software | 6.0(4) |
| cisco | webns | 7.10_.0.06s |
| neoteris | instant_virtual_extranet | 3.3 |
| 4d | webstar | 4.0 |
| cisco | pix_firewall_software | 6.1(1) |
| checkpoint | vpn-1 | next_generation_fp2 |
| cisco | ios | 12.2sy |
| cisco | pix_firewall_software | 6.0 |
| avaya | vsu | 5000_r2.0.1 |
| openssl | openssl | 0.9.7b |
| cisco | pix_firewall_software | 6.2(3.100) |
| openssl | openssl | 0.9.6h |
| hp | apache-based_web_server | 2.0.43.00 |
| cisco | webns | 6.10 |
| avaya | vsu | 5x |
| openssl | openssl | 0.9.6g |
| dell | bsafe_ssl-j | 3.0 |
| cisco | css_secure_content_accelerator | 1.0 |
| securecomputing | sidewinder | 5.2 |
| checkpoint | vpn-1 | vsx_ng_with_application_intelligence |
| dell | bsafe_ssl-j | 3.0.1 |
| cisco | pix_firewall_software | 6.1(2) |
| avaya | intuity_audix | s3210 |
| novell | imanager | 1.5 |
| openssl | openssl | 0.9.6i |
| novell | edirectory | 8.7.1 |
| openssl | openssl | 0.9.6d |
| securecomputing | sidewinder | 5.2.1 |
| forcepoint | stonegate | 2.2.1 |
| novell | edirectory | 8.0 |
| cisco | gss_4480_global_site_selector | * |
| cisco | pix_firewall_software | 6.1(3) |
| redhat | enterprise_linux | 3.0 |
| avaya | intuity_audix | * |
| checkpoint | firewall-1 | next_generation_fp1 |
| avaya | vsu | 500 |
| redhat | linux | 7.3 |
| cisco | ciscoworks_common_management_foundation | 2.1 |
| checkpoint | vpn-1 | next_generation_fp0 |
| cisco | pix_firewall_software | 6.3(3.102) |
| securecomputing | sidewinder | 5.2.0.03 |
| checkpoint | vpn-1 | next_generation_fp1 |
| hp | aaa_server | * |
| cisco | firewall_services_module | * |
| 4d | webstar | 5.3 |
| avaya | sg5 | 4.2 |
| cisco | firewall_services_module | 1.1.3 |
| cisco | gss_4490_global_site_selector | * |
| novell | imanager | 2.0 |
| forcepoint | stonegate | 2.0.9 |
| cisco | pix_firewall_software | 6.1(5) |
| apple | mac_os_x_server | 10.3.3 |
| stonesoft | stonebeat_webcluster | 2.5 |
| stonesoft | stonebeat_webcluster | 2.0 |
| redhat | enterprise_linux_desktop | 3.0 |
| avaya | sg200 | 4.4 |
Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | openmanage | 3.4 |
| dell | openmanage | 3.2 |
| dell | openmanage | 3.7.1 |
| dell | openmanage | 3.7 |
Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which allows local users to gain privileges by accessing the Help functionality.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | truemobile_1300_wlan_mini-pci_card_util_trayapplet | 3.10.39.0 |
Dell TrueMobile 2300 Wireless Broadband Router running firmware 3.0.0.8 and 5.1.1.6, and possibly other versions, allows remote attackers to reset authentication credentials, then change configuration or firmware, via a direct request to apply.cgi with the Page parameter set to adv_password.asp.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | truemobile_2300_wireless_broadband_router | 3.0.0.8 |
| dell | truemobile_2300_wireless_broadband_router | 5.1.1.6 |
Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, allows remote attackers to use the FTP printing interface as a proxy ("FTP bounce") by using arbitrary PORT arguments to connect to systems for which access would be otherwise restricted.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| fuji_xerox | phaser_6201j | * |
| fuji_xerox | docuprint_211_network_option_card | * |
| fuji_xerox | docuprint_c2535a | * |
| fuji_xerox | docuprint_181 | * |
| fuji_xerox | docuprint_c830 | * |
| dell | 3000cn | * |
| fuji_xerox | docuprint_181_network_option_card | * |
| fuji_xerox | fuji_xerox_printing_systems_print_engine | * |
| dell | 3010cn | * |
| fuji_xerox | docuprint_c525a | * |
| fuji_xerox | docuprint_c525a_network_option_card | * |
| dell | 5110cn | * |
| fuji_xerox | docuprint_c1616 | * |
| dell | 3110cn | * |
| fuji_xerox | docuprint_211 | * |
| dell | 3100cn | * |
| dell | 5100cn | * |
| fuji_xerox | docuprint_c1616_network_option_card | * |
| fuji_xerox | docuprint_c830_network_option_card | * |
The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, does not properly perform authentication for HTTP requests, which allows remote attackers to modify system configuration via crafted requests, including changing the administrator password or causing a denial of service to the print server.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| fuji_xerox | phaser_6201j | * |
| fuji_xerox | docuprint_211_network_option_card | * |
| fuji_xerox | docuprint_c2535a | * |
| fuji_xerox | docuprint_181 | * |
| fuji_xerox | docuprint_c830 | * |
| dell | 3000cn | * |
| fuji_xerox | docuprint_181_network_option_card | * |
| fuji_xerox | fuji_xerox_printing_systems_print_engine | * |
| dell | 3010cn | * |
| fuji_xerox | docuprint_c525a | * |
| fuji_xerox | docuprint_c525a_network_option_card | * |
| dell | 5110cn | * |
| fuji_xerox | docuprint_c1616 | * |
| dell | 3110cn | * |
| fuji_xerox | docuprint_211 | * |
| dell | 3100cn | * |
| dell | 5100cn | * |
| fuji_xerox | docuprint_c1616_network_option_card | * |
| fuji_xerox | docuprint_c830_network_option_card | * |
The Dell Openmanage CD launches X11 and SSH daemons that do not require authentication, which allows remote attackers to gain privileges.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | openmanage_cd | * |
The RSA Crypto-C before 6.3.1 and Cert-C before 2.8 libraries, as used by RSA BSAFE, multiple Cisco products, and other products, allows remote attackers to cause a denial of service via malformed ASN.1 objects.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_crypto-c | * |
| dell | bsafe_cert-c | * |
Unspecified vulnerability in Dell Remote Access Card 4 (DRAC4) with firmware 1.50 Build 02.16 allows remote attackers to cause a denial of service (SSH daemon crash) via certain network traffic, as demonstrated by an "nmap -O" scan with nmap 4.03, possibly related to a Mocana (Mocanada) SSH vulnerability.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | remote_access_card | 4 |
The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_crypto-c-micro-edition | * |
| dell | bsafe_crypto-j | 5.0 |
| dell | bsafe_crypto-j | 5.0.1 |
Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) the User-Agent HTTP header to hserver.dll or (2) unspecified input to hagent.exe.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | wyse_device_manager | 4.7.1 |
| dell | wyse_device_manager | 4.7.0 |
| dell | wyse_device_manager | 4.7.2 |
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | wyse_device_manager | 4.7.1 |
| dell | wyse_device_manager | 4.7.0 |
| dell | wyse_device_manager | 4.7.2 |
Directory traversal vulnerability in the GetData method in the Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 allows remote attackers to read arbitrary files via directory traversal sequences in the fileID parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | dellsystemlite.scanner_activex_control | 1.0.0.0 |
The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest property, which allows remote attackers to execute arbitrary WMI Query Language (WQL) statements via a crafted value, as demonstrated by a value that triggers disclosure of information about installed software.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | dellsystemlite.scanner_activex_control | 1.0.0.0 |
The Dell KACE K2000 Systems Deployment Appliance 3.3.36822 and earlier contains a peinst CIFS share, which allows remote attackers to obtain sensitive information by reading the (1) unattend.xml or (2) sysprep.inf file, as demonstrated by reading a password.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | kace_k2000_systems_deployment_appliance | * |
The Dell KACE K2000 System Deployment Appliance stores the recovery account password in cleartext within a PHP script, which allows context-dependent attackers to obtain sensitive information by examining script source code.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | kace_k2000_systems_deployment_appliance | * |
The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | kace_k2000_systems_deployment_appliance | * |
The Dell KACE K2000 System Deployment Appliance has a default username and password for the read-only reporting account, which makes it easier for remote attackers to obtain sensitive information from the database by leveraging the default credentials.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | kace_k2000_systems_deployment_appliance | * |
Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface on the Dell KACE K2000 System Deployment Appliance allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | kace_k2000_systems_deployment_appliance | * |
SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2 allows remote attackers to execute arbitrary SQL commands via the scheduleID parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | sonicwall_viewpoint | 6.0 |
Absolute path traversal vulnerability in logShow.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to read arbitrary files via a full pathname in the file parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| quantum | scalar_i500_firmware | sp4 |
| quantum | scalar_i500_firmware | i5 |
| quantum | scalar_i500_firmware | i7.0.1 |
| quantum | scalar_i500_firmware | i7 |
| dell | powervault_ml6000 | 41u |
| dell | powervault_ml6000 | 32u |
| quantum | scalar_i500_firmware | i4 |
| quantum | scalar_i500_firmware | i6 |
| quantum | scalar_i500_firmware | sp4.2 |
| quantum | scalar_i500_firmware | i5.1 |
| quantum | scalar_i500_firmware | i6.1 |
| dell | powervault_ml6010 | 5u |
| quantum | scalar_i500_firmware | i3.1 |
| dell | powervault_ml6020 | 14u |
| quantum | scalar_i500_firmware | i2 |
| quantum | scalar_i500 | 5u |
| dell | powervault_ml6000_firmware | 585g.gs003 |
| quantum | scalar_i500 | 23u |
| quantum | scalar_i500_firmware | i3 |
| quantum | scalar_i500 | 14u |
| dell | powervault_ml6030 | 23u |
| quantum | scalar_i500_firmware | * |
Cross-site scripting (XSS) vulnerability in checkQKMProg.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| quantum | scalar_i500_firmware | sp4 |
| quantum | scalar_i500_firmware | i5 |
| quantum | scalar_i500_firmware | i7.0.1 |
| quantum | scalar_i500_firmware | i7 |
| dell | powervault_ml6000 | 41u |
| dell | powervault_ml6000 | 32u |
| quantum | scalar_i500_firmware | i4 |
| quantum | scalar_i500_firmware | i6 |
| quantum | scalar_i500_firmware | sp4.2 |
| quantum | scalar_i500_firmware | i5.1 |
| quantum | scalar_i500_firmware | i6.1 |
| dell | powervault_ml6010 | 5u |
| quantum | scalar_i500_firmware | i3.1 |
| dell | powervault_ml6020 | 14u |
| quantum | scalar_i500_firmware | i2 |
| quantum | scalar_i500 | 5u |
| dell | powervault_ml6000_firmware | 585g.gs003 |
| quantum | scalar_i500 | 23u |
| quantum | scalar_i500_firmware | i3 |
| quantum | scalar_i500 | 14u |
| dell | powervault_ml6030 | 23u |
| quantum | scalar_i500_firmware | * |
Cross-site request forgery (CSRF) vulnerability in saveRestore.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to hijack the authentication of users for requests that execute Linux commands via the fileName parameter, related to a "command-injection vulnerability."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| quantum | scalar_i500_firmware | sp4 |
| quantum | scalar_i500_firmware | i5 |
| quantum | scalar_i500_firmware | i7.0.1 |
| quantum | scalar_i500_firmware | i7 |
| dell | powervault_ml6000 | 41u |
| dell | powervault_ml6000 | 32u |
| quantum | scalar_i500_firmware | i4 |
| quantum | scalar_i500_firmware | i6 |
| quantum | scalar_i500_firmware | sp4.2 |
| quantum | scalar_i500_firmware | i5.1 |
| quantum | scalar_i500_firmware | i6.1 |
| dell | powervault_ml6010 | 5u |
| quantum | scalar_i500_firmware | i3.1 |
| dell | powervault_ml6020 | 14u |
| quantum | scalar_i500_firmware | i2 |
| quantum | scalar_i500 | 5u |
| dell | powervault_ml6000_firmware | 585g.gs003 |
| quantum | scalar_i500 | 23u |
| quantum | scalar_i500_firmware | i3 |
| quantum | scalar_i500 | 14u |
| dell | powervault_ml6030 | 23u |
| quantum | scalar_i500_firmware | * |
The Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100) and the IBM TS3310 tape library with firmware before R6C (606G.GS001), uses default passwords for unspecified user accounts, which makes it easier for remote attackers to obtain access via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| quantum | scalar_i500_firmware | sp4 |
| quantum | scalar_i500_firmware | i7.0.1 |
| ibm | ts3310_tape_library_firmware | * |
| quantum | scalar_i500_firmware | i7 |
| dell | powervault_ml6000 | 41u |
| quantum | scalar_i500_firmware | i4 |
| quantum | scalar_i500_firmware | sp4.2 |
| quantum | scalar_i500_firmware | i5.1 |
| quantum | scalar_i500_firmware | i6.1 |
| quantum | scalar_i500_firmware | i3.1 |
| quantum | scalar_i500_firmware | i2 |
| quantum | scalar_i500_firmware | i3 |
| quantum | scalar_i500 | 14u |
| dell | powervault_ml6030 | 23u |
| ibm | ts3310_tape_library | 3576 |
| quantum | scalar_i500_firmware | i5 |
| dell | powervault_ml6000 | 32u |
| quantum | scalar_i500_firmware | i6 |
| dell | powervault_ml6010 | 5u |
| dell | powervault_ml6020 | 14u |
| quantum | scalar_i500 | 5u |
| dell | powervault_ml6000_firmware | 585g.gs003 |
| quantum | scalar_i500 | 23u |
| ibm | ts3310_tape_library | 3573 |
| quantum | scalar_i500_firmware | * |
The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, possibly 1.4 and earlier, allows local users to execute arbitrary shell commands via vectors related to "insecure handling of tmp files" and predictable file names.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | crowbar | * |
Cross-site scripting (XSS) vulnerability in crowbar_framework/app/views/support/index.html.haml in the Crowbar barclamp in Crowbar, possibly 1.4 and earlier, allows remote attackers to inject arbitrary web script or HTML via the file parameter to /utils.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | crowbar | * |
Cross-site scripting (XSS) vulnerability in Dell OpenManage Server Administrator (OMSA) before 6.5.0.1, 7.0 before 7.0.0.1, and 7.1 before 7.1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | openmanage_server_administrator | 5.2.0 |
| dell | openmanage_server_administrator | 4.4.0 |
| dell | openmanage_server_administrator | 6.4.0 |
| dell | openmanage_server_administrator | 1.00.0000 |
| dell | openmanage_server_administrator | 5.1.0 |
| dell | openmanage_server_administrator | 7.0.0 |
| dell | openmanage_server_administrator | 5.1.0.1 |
| dell | openmanage_server_administrator | 5.5.0 |
| dell | openmanage_server_administrator | 7.1.0 |
| dell | openmanage_server_administrator | 6.3.0 |
| dell | openmanage_server_administrator | 5.0.0 |
| dell | openmanage_server_administrator | 5.4.0 |
| dell | openmanage_server_administrator | * |
| dell | openmanage_server_administrator | 4.3.0 |
| dell | openmanage_server_administrator | 5.5.0.1 |
| dell | openmanage_server_administrator | 4.5.0 |
| dell | openmanage_server_administrator | 5.3.0 |
| dell | openmanage_server_administrator | 6.2.0 |
Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote attackers to inject arbitrary web script or HTML via the topic parameter to html/index_main.htm in (1) help/sm/en/Output/wwhelp/wwhimpl/js/, (2) help/sm/es/Output/wwhelp/wwhimpl/js/, (3) help/sm/ja/Output/wwhelp/wwhimpl/js/, (4) help/sm/de/Output/wwhelp/wwhimpl/js/, (5) help/sm/fr/Output/wwhelp/wwhimpl/js/, (6) help/sm/zh/Output/wwhelp/wwhimpl/js/, (7) help/hip/en/msgguide/wwhelp/wwhimpl/js/, or (8) help/hip/en/msgguide/wwhelp/wwhimpl/common/.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | openmanage_server_administrator | 7.1.0.1 |
| dell | openmanage_server_administrator | 7.0.0.1 |
| dell | openmanage_server_administrator | 6.5.0.1 |
The web interface on Dell PowerConnect 6248P switches allows remote attackers to cause a denial of service (device crash) via a malformed request.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | powerconnect_6248p | - |
Open redirect vulnerability in Dell OpenManage Server Administrator (OMSA) before 7.3.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the file parameter to HelpViewer.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | openmanage_server_administrator | 7.1.0.1 |
| dell | openmanage_server_administrator | * |
| dell | openmanage_server_administrator | 7.0.0.1 |
| dell | openmanage_server_administrator | 7.0.0 |
| dell | openmanage_server_administrator | 7.1.0 |
EMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows local users to discover the cleartext LDAP bind password by reading the console.
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_unisphere | * |
| dell | emc_unisphere | 1.0 |
| dell | emc_unisphere | 1.5 |
| dell | emc_unisphere | 1.1 |
Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | equallogic_ps4000_firmware | 6.0 |
Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges and providing a crafted rbu_packet.pktNum value in conjunction with a crafted rbu_packet.pktSize value.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | latitude_e6400 | - |
| dell | latitude_e6400_atg_xfr | - |
| dell | latitude_e6500 | - |
| dell | precision_m6400 | - |
| dell | precision_m2400 | - |
| dell | latitude_e4300 | - |
| dell | precision_m4400 | - |
| dell | latitude_e5500 | - |
| dell | precision_m6500 | - |
| dell | latitude_d830 | - |
| dell | latitude_xt2 | - |
| dell | latitude_e5400 | - |
| dell | latitude_d630 | - |
| dell | precision_m2300 | - |
| dell | latitude_e4200 | - |
| dell | precision_m4300 | - |
| dell | latitude_d530 | - |
| dell | latitude_d631 | - |
| dell | precision_m6300 | - |
| dell | latitude_z600 | - |
| dell | latitude_d531 | - |
| dell | latitude_e6400_atg | - |
Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | idrac7_firmware | * |
| dell | idrac7_firmware | 1.10.10 |
| dell | idrac7_firmware | 1.20.20 |
| dell | idrac6_firmware | * |
| dell | idrac6_firmware | 1.6 |
| dell | idrac6_firmware | 1.8 |
| dell | idrac7_firmware | 1.23.23 |
| dell | idrac6_firmware | 1.2 |
| dell | idrac7_firmware | 1.06.06 |
| dell | idrac6_firmware | 1.0 |
| dell | idrac7_firmware | 1.00.00 |
| dell | idrac6_firmware | 1.3 |
| dell | idrac7 | - |
| dell | idrac6_firmware | 1.1 |
| dell | idrac6_monolithic | - |
| dell | idrac6_firmware | 1.5 |
| dell | idrac7_firmware | 1.37.35 |
The SSH service on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of service (device reset) or possibly execute arbitrary code by sending many packets to TCP port 22.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | powerconnect_3348 | 1.2.1.3 |
| dell | powerconnect_3524p | 2.0.0.48 |
| dell | powerconnect_5324 | 2.0.1.4 |
The OpenManage web application 2.5 build 1.19 on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote authenticated users to cause a denial of service (device reset) via a direct request to an unspecified OSPF URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | powerconnect_3348 | 1.2.1.3 |
| dell | powerconnect_3524p | 2.0.0.48 |
| dell | powerconnect_5324 | 2.0.1.4 |
The login page in the GoAhead web server on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of service (device outage) via a long username.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | powerconnect_3348 | 1.2.1.3 |
| dell | powerconnect_3524p | 2.0.0.48 |
| dell | powerconnect_5324 | 2.0.1.4 |
The Dell iDRAC6 with firmware 1.x before 1.92 and 2.x and 3.x before 3.42, and iDRAC7 with firmware before 1.23.23, allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password. NOTE: the vendor disputes the significance of this issue, stating "DRAC's are intended to be on a separate management network; they are not designed nor intended to be placed on or connected to the Internet."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | idrac6_bmc | * |
The web interface on the Dell iDRAC6 with firmware before 1.95 allows remote attackers to modify the CLP interface for arbitrary users and possibly have other impact via a request to an unspecified form that is accessible from testurls.html. NOTE: the vendor disputes the significance of this issue, stating "DRAC's are intended to be on a separate management network; they are not designed nor intended to be placed on or connected to the Internet."
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | idrac6_firmware | 1.7 |
The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's full name) by sending a login request with a valid domain and username but without the CaptchaType, UseCaptchaEveryTime, and CaptchaResponse parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | quest_one_password_manager | 5.0 |
Cross-site scripting (XSS) vulnerability in adminui/user_list.php on the Dell KACE K1000 management appliance 5.5.90545 allows remote attackers to inject arbitrary web script or HTML via the LABEL_ID parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | kace_k1000_systems_management_appliance | - |
| dell | kace_k1000_systems_management_appliance_software | 5.5.90545 |
The SSLSocket implementation in the (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to cause a denial of service (memory consumption) by triggering application-data processing during the TLS handshake, a time at which the data is internally buffered.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| emc | rsa_bsafe_ssl-j | 5.0 |
| emc | rsa_bsafe_ssl-j | 5.1.0 |
| emc | rsa_bsafe_ssl-j | 5.1.1 |
| emc | rsa_bsafe_ssl-j | 6.0.1 |
| dell | bsafe_ssl-j | 6.0 |
| dell | bsafe_ssl-j | 5.1.2 |
The (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 make it easier for remote attackers to bypass intended cryptographic protection mechanisms by triggering application-data processing during the TLS handshake, a time at which the data is both unencrypted and unauthenticated.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| emc | rsa_bsafe_ssl-j | 5.0 |
| emc | rsa_bsafe_ssl-j | 5.1.0 |
| emc | rsa_bsafe_ssl-j | 5.1.1 |
| emc | rsa_bsafe_ssl-j | 6.0.1 |
| dell | bsafe_ssl-j | 6.0 |
| dell | bsafe_ssl-j | 5.1.2 |
The SSLEngine API implementation in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to trigger the selection of a weak cipher suite by using the wrap method during a certain incomplete-handshake state.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| emc | rsa_bsafe_ssl-j | 5.0 |
| emc | rsa_bsafe_ssl-j | 5.1.0 |
| emc | rsa_bsafe_ssl-j | 5.1.1 |
| emc | rsa_bsafe_ssl-j | 6.0.1 |
| dell | bsafe_ssl-j | 6.0 |
| dell | bsafe_ssl-j | 5.1.2 |
The server in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.5 does not properly process certificate chains, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_micro-edition-suite | 4.0.0 |
| dell | bsafe_micro-edition-suite | 4.0.1 |
| dell | bsafe_micro-edition-suite | 4.0.4 |
| dell | bsafe_micro-edition-suite | 4.0.2 |
| dell | bsafe_micro-edition-suite | 4.0.3 |
EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate chain.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_micro-edition-suite | 3.2.4 |
| dell | bsafe_micro-edition-suite | 4.0.0 |
| dell | bsafe_micro-edition-suite | 3.2.5 |
| dell | bsafe_micro-edition-suite | 3.2.3 |
| dell | bsafe_micro-edition-suite | 4.0.1 |
| dell | bsafe_micro-edition-suite | 4.0.4 |
| dell | bsafe_micro-edition-suite | 3.2.2 |
| dell | bsafe_micro-edition-suite | 4.0.2 |
| dell | bsafe_micro-edition-suite | 4.0.3 |
| dell | bsafe_micro-edition-suite | 3.2.0 |
| dell | bsafe_micro-edition-suite | 3.2.1 |
Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the macAddress element in a (1) getUploadPath or (2) getKBot SOAP request to service/kbot_service.php; the ID parameter to (3) userui/advisory_detail.php or (4) userui/ticket.php; and the (5) ORDER[] parameter to userui/ticket_list.php.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | kace_k1000_systems_management_virtual_appliance | - |
| dell | kace_k1200s_systems_management_appliance | - |
| dell | kace_k1100s_systems_management_appliance | - |
| dell | kace_k1000_systems_management_appliance | - |
| dell | kace_k1000_systems_management_appliance_software | 5.4.76847 |
logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| quantum | scalar_i500 | 5u |
| dell | powervault_ml6000 | 41u |
| dell | powervault_ml6000_firmware | * |
| quantum | scalar_i500 | 23u |
| dell | powervault_ml6000 | 32u |
| quantum | scalar_i500 | 14u |
| quantum | scalar_i500_firmware | * |
The TLS implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) sends a long series of random bytes during use of the Dual_EC_DRBG algorithm, which makes it easier for remote attackers to obtain plaintext from TLS sessions by recovering the algorithm's inner state, a different issue than CVE-2007-6755.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_share | - |
The Dual_EC_DRBG implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) processes certain requests for output bytes by considering only the requested byte count and not the use of cached bytes, which makes it easier for remote attackers to obtain plaintext from TLS sessions by recovering the algorithm's inner state, a different issue than CVE-2007-6755.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_share | - |
The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random extension during use of the Dual_EC_DRBG algorithm, which makes it easier for remote attackers to obtain plaintext from TLS sessions by requesting long nonces from a server, a different issue than CVE-2007-6755.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_share | - |
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.6 and RSA BSAFE SSL-J before 6.1.4 do not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_micro-edition-suite | 4.0.0 |
| dell | bsafe_micro-edition-suite | 4.0.5 |
| dell | bsafe_ssl-j | * |
| dell | bsafe_micro-edition-suite | 4.0.1 |
| dell | bsafe_micro-edition-suite | 4.0.4 |
| dell | bsafe_micro-edition-suite | 4.0.2 |
| dell | bsafe_micro-edition-suite | 4.0.3 |
The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | idrac7 | * |
| dell | idrac6_modular | * |
| dell | idrac6_monolithic | * |
| intel | ipmi | 1.5 |
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3 and RSA BSAFE SSL-C 2.8.9 and earlier allow remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigger a loss of forward secrecy by omitting the ServerKeyExchange message, a similar issue to CVE-2014-3572.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_ssl-c | * |
| dell | bsafe | * |
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA BSAFE SSL-C 2.8.9 and earlier do not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, a similar issue to CVE-2014-8275.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-295,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_ssl-j | * |
| dell | bsafe_ssl-c | * |
| dell | bsafe | * |
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3 and RSA BSAFE SSL-C 2.8.9 and earlier do not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a similar issue to CVE-2015-0204.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_ssl-c | * |
| dell | bsafe | * |
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3 and RSA BSAFE SSL-C 2.8.9 and earlier, when client authentication and an ephemeral Diffie-Hellman ciphersuite are enabled, allow remote attackers to cause a denial of service (daemon crash) via a ClientKeyExchange message with a length of zero, a similar issue to CVE-2015-1787.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_ssl-c | * |
| dell | bsafe | * |
Integer underflow in the base64-decoding implementation in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-C Micro Edition (Crypto-C ME) before 4.0.4 and 4.1, and RSA BSAFE SSL-C 2.8.9 and earlier allows remote attackers to cause a denial of service (memory corruption or segmentation fault) or possibly have unspecified other impact via crafted base64 data, a similar issue to CVE-2015-0292.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-191,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_ssl-c | * |
| dell | bsafe_crypto-c | * |
| dell | bsafe | * |
Multiple SQL injection vulnerabilities in Dell ScriptLogic Asset Manager (aka Quest Workspace Asset Manager) before 9.5 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to (1) GetClientPackage.aspx or (2) GetProcessedPackage.aspx.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | asset_manager | * |
The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.0 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H | 0.8 | 5.2 |
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bios | * |
| dell | bios | a13 |
The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which makes it easier for local users to discover credentials by leveraging administrative access.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.7 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H | 0.8 | 5.9 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | vce_vision_intelligent_operations | * |
The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon a request for the Settings screen, which allows remote attackers to discover the admin user password by sniffing the network.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | vce_vision_intelligent_operations | * |
Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted template string specifiers in a serialized object, which triggers a heap-based buffer overflow.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | netvault_backup | 10.0.5 |
Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | netvault_backup | * |
Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (device reload) via malformed STUN packets, aka Bug ID CSCuv01348.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | gs1900-10hp_firmware | * |
| netgear | jr6150_firmware | * |
| dell | emc_powerscale_onefs | 8.2.2 |
| zzinc | keymouse_firmware | 3.08 |
Dell Pre-Boot Authentication Driver (PBADRV.sys) 1.0.1.5 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x0022201c IOCTL call.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | pre-boot_authentication_driver | 1.0.1.5 |
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | integrated_remote_access_controller_firmware | * |
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-134,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | integrated_remote_access_controller_firmware | * |
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long SSH username or input.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | integrated_remote_access_controller_firmware | * |
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | integrated_remote_access_controller_firmware | * |
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrative HTTP commands.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | integrated_remote_access_controller_firmware | * |
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | integrated_remote_access_controller_firmware | * |
Dell SonicWall TotalSecure TZ 100 devices with firmware before 5.9.1.0-22o allow remote attackers to cause a denial of service via a crafted packet.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | sonicwall_totalsecure_tz_100_firmware | * |
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x and 4.1.x before 4.1.5, RSA BSAFE Crypto-C Micro Edition (CCME) 4.0.x and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2.1, RSA BSAFE SSL-J before 6.2.1, and RSA BSAFE SSL-C before 2.8.9 allow remote attackers to discover a private-key prime by conducting a Lenstra side-channel attack that leverages an application's failure to detect an RSA signature failure during a TLS session.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_micro-edition-suite | * |
| dell | bsafe_crypto-c-micro-edition | * |
| dell | bsafe_ssl-j | * |
| dell | bsafe_ssl-c | * |
| dell | bsafe_crypto-j | * |
An HTTP servlet in vApp Manager in EMC Unisphere for VMAX Virtual Appliance before 8.2.0 allows remote attackers to write to arbitrary files via a crafted pathname.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_unisphere | * |
EMC Data Domain OS 5.4 through 5.7 before 5.7.2.0 has a default no_root_squash option for NFS exports, which makes it easier for remote attackers to obtain filesystem access by leveraging client root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_data_domain_os | * |
EMC Data Domain OS 5.4 through 5.7 before 5.7.2.0 allows remote authenticated users to bypass intended password-change restrictions by leveraging access to (1) a different account with the same role as a target account or (2) an account's session at an unattended workstation.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_data_domain_os | * |
The client in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.9 and 4.1.x before 4.1.5 places the weakest algorithms first in a signature-algorithm list transmitted to a server, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging server behavior in which the first algorithm is used.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe | * |
The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequence of IPv6 packets, aka Bug ID CSCuu46673.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| samsung | x14j_firmware | t-ms14jakucb-1102.5 |
| zyxel | gs1900-10hp_firmware | * |
| netgear | jr6150_firmware | * |
| dell | emc_powerscale_onefs | 8.2.2 |
| zzinc | keymouse_firmware | 3.08 |
Dell SecureWorks app before 2.1 for iOS does not validate SSL certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | secureworks | 2.0.6 |
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary files via a ..\ (dot dot backslash) in the file parameter to ViewFile.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | openmanage_server_administrator | 8.2 |
Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-74,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | idrac7_firmware | * |
| dell | idrac8_firmware | * |
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.5 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N | 2.8 | 3.6 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| amazonbasics | firmware | - |
| dell | km714_firmware | * |
| lenovo | ultraslim_firmware | - |
| dell | km632_firmware | - |
| logitech | unifying_firmware | * |
The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote authenticated users to execute arbitrary code via crafted input to the (1) GeneralCmdRequest, (2) PersistantDataRequest, or (3) GetCommandExecRequest class.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_unisphere | 8.2 |
| dell | emc_unisphere | 8.0 |
| dell | emc_unisphere | 8.1.2 |
| dell | emc_unisphere | 8.1 |
| emc | solutions_enabler | 8.1 |
| emc | solutions_enabler | 8.1.2 |
| emc | solutions_enabler | 8.0 |
| emc | unisphere | 8.0.3 |
| emc | solutions_enabler | 8.2 |
| emc | solutions_enabler | 8.0.3 |
The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote attackers to execute arbitrary code via crafted input to the (1) GetSymmCmdRequest or (2) RemoteServiceHandler class.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_unisphere | 8.2 |
| emc | solutions_enabler | 8.3 |
| dell | emc_unisphere | 8.0 |
| dell | emc_unisphere | 8.1.2 |
| dell | emc_unisphere | 8.1 |
| emc | solutions_enabler | 8.1 |
| emc | solutions_enabler | 8.1.2 |
| emc | solutions_enabler | 8.0 |
| emc | unisphere | 8.0.3 |
| emc | solutions_enabler | 8.0.3 |
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file. A malicious administrator with configuration privileges may access this sensitive system file and compromise the affected system.
CVSS 2.0
Severity: LOW
Problem Type: CWE-275,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| emc | recoverpoint | * |
| dell | recoverpoint_for_virtual_machines | * |
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface and escalate his privileges to root.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| emc | recoverpoint | * |
| dell | recoverpoint_for_virtual_machines | * |
EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| emc | recoverpoint | * |
| dell | recoverpoint_for_virtual_machines | * |
EMC Data Protection Advisor 6.1.x, EMC Data Protection Advisor 6.2, EMC Data Protection Advisor 6.2.1, EMC Data Protection Advisor 6.2.2, EMC Data Protection Advisor 6.2.3 prior to patch 446 has a path traversal vulnerability that may potentially be exploited by malicious users to compromise the affected system.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_data_protection_advisor | 6.1 |
| dell | emc_data_protection_advisor | 6.2.2 |
| dell | emc_data_protection_advisor | 6.2 |
| dell | emc_data_protection_advisor | 6.2.1 |
| dell | emc_data_protection_advisor | 6.2.3 |
An issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6.2.2. There is an Improper OCSP Validation Vulnerability. OCSP responses have two time values: thisUpdate and nextUpdate. These specify a validity period; however, both values are optional. Crypto-J treats the lack of a nextUpdate as indicating that the OCSP response is valid indefinitely instead of restricting its validity for a brief period surrounding the thisUpdate time. This vulnerability is similar to the issue described in CVE-2015-4748.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-404,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_crypto-j | * |
EMC Data Domain OS (DD OS) 5.4 all versions, EMC Data Domain OS (DD OS) 5.5 family all versions prior to 5.5.5.0, EMC Data Domain OS (DD OS) 5.6 family all versions prior to 5.6.2.0, EMC Data Domain OS (DD OS) 5.7 family all versions prior to 5.7.2.10 has a command injection vulnerability that could potentially be exploited by malicious users to compromise the affected system.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.7 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H | 0.8 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_data_domain_os | 5.6 |
| dell | emc_data_domain_os | 5.7 |
| dell | emc_data_domain_os | 5.4 |
| dell | emc_data_domain_os | 5.5 |
EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could be carried out by modifying a PKCS#12 file that has an integrity MAC for which the password is not known. An attacker could then feed the modified PKCS#12 file to the toolkit and guess the current MAC one byte at a time. This is possible because Crypto-J uses a non-constant-time method to compare the stored MAC with the calculated MAC. This vulnerability is similar to the issue described in CVE-2015-2601.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N | 2.2 | 1.4 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_crypto-j | * |
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system. The application doesn't properly escape the information passed in the 'tsrDeleteRestartedFile' or 'currentTSREmailTo' variables before making a call to system(), allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | sonicwall_secure_remote_access_server | 8.1.0.2-14sv |
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'extensionsettings' CGI (/cgi-bin/extensionsettings) component responsible for handling some of the server's internal configurations. The CGI application doesn't properly escape the information it's passed when processing a particular multi-part form request involving scripts. The filename of the 'scriptname' variable is read in unsanitized before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account. This is SonicWall Issue ID 181195.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | sonicwall_secure_remote_access_server | 8.1.0.2-14sv |
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'viewcert' CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application doesn't properly escape the information it's passed in the 'CERT' variable before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | sonicwall_secure_remote_access_server | 8.1.0.2-14sv |
Directory Traversal in Dell Storage Manager 2016 R2.1 causes Information Disclosure when the doGet method of the EmWebsiteServlet class doesn't properly validate user provided path before using it in file operations. Was ZDI-CAN-4459.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | storage_manager_2016 | r2.1 |
The SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with the knowledge of the password might potentially disable the SMI-S service via HTTP requests, affecting storage management and monitoring functionality via the SMI-S interface. This issue, aka DSM-30415, only affects a Windows installation of the Data Collector (not applicable to the virtual appliance).
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | storage_manager | * |
EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier) contain an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-290,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_unisphere | * |
| emc | vasa | * |
| emc | solutions_enabler | * |
| emc | vmax_emanagement | * |
In Dell EMC VNX2 versions prior to Operating Environment for File 8.1.9.217 and VNX1 versions prior to Operating Environment for File 7.1.80.8, a web server error page in VNX Control Station is impacted by a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to execute arbitrary HTML code in the user's browser session in the context of the affected web application.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_vnx2_firmware | * |
| dell | emc_vnx1_firmware | * |
In Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability. A remote malicious user could potentially exploit this vulnerability to read unauthorized files by supplying specially crafted strings in input parameters of the application. A malicious user cannot delete or modify any files via this vulnerability.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | storage_manager | * |
The web user interface of Dell 2335dn and 2355dn Multifunction Laser Printers, firmware versions prior to V2.70.06.26 A13 and V2.70.45.34 A10 respectively, are affected by a cross-site scripting vulnerability. Attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected website.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | 2335dn_firmware | * |
| dell | 2355dn_firmware | * |
An exploitable dll hijacking vulnerability exists in the poaService.exe service component of the Dell Precision Optimizer software version 3.5.5.0. A specifically named malicious dll file located in one of directories pointed to by the PATH environment variable will lead to privilege escalation. An attacker with local access to vulnerable system can exploit this vulnerability.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-426,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | precision_optimizer | 3.5.5.0 |
EMC RSA BSAFE Cert-C before 2.9.0.5 contains a potential improper certificate processing vulnerability.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-295,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_cert-c | * |
EMC Data Domain OS 5.2 through 5.7 before 5.7.3.0 and 6.0 before 6.0.1.0 is affected by a privilege escalation vulnerability that may potentially be exploited by attackers to compromise the affected system.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_data_domain_os | 5.6 |
| dell | emc_data_domain_os | 5.7 |
| dell | emc_data_domain_os | 5.4 |
| dell | emc_data_domain_os | 5.2 |
| dell | emc_data_domain_os | 6.0 |
| dell | emc_data_domain_os | 5.5 |
EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code execution vulnerability that could potentially be exploited by malicious users to compromise the affected system.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_vasa_provider_virtual_appliance | * |
An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials of the ScaleIO MDM user who executed the script in clear text in temporary log files. The temporary files may potentially be read by an unprivileged user with access to the server where the script was executed to recover exposed credentials.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 8.4 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 2.5 | 5.9 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_scaleio | 2.0.1.3 |
| dell | emc_scaleio | 2.0.1.1 |
| dell | emc_scaleio | 2.0.1.2 |
| dell | emc_scaleio | 2.0.1.0 |
In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete data, by supplying specially crafted strings in input parameters of the web service call.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 2.8 | 5.9 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_vipr_srm | * |
| dell | emc_vnx_monitoring_and_reporting | * |
| dell | emc_m&r | * |
| dell | emc_storage_monitoring_and_reporting | * |
EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with default passwords for Webservice Gateway and RMI JMX components. A remote attacker with the knowledge of the default password may potentially use these accounts to run arbitrary web service and remote procedure calls on the affected system.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_storage_monitoring_and_reporting | 4.0.2 |
| dell | emc_vipr_srm | * |
| dell | emc_m&r | - |
| dell | emc_vnx_monitoring_and_reporting | - |
In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Java Management Extensions (JMX) protocol used to communicate between components in the Alerting and/or Compliance components can be leveraged to create a denial of service (DoS) condition. Attackers with knowledge of JMX agent user credentials could potentially exploit this vulnerability to create arbitrary files on the affected system and create a DoS condition by leveraging inherent JMX protocol capabilities.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.4 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H | 2.2 | 5.2 |
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_vipr_srm | * |
| dell | emc_vnx_monitoring_and_reporting | * |
| dell | emc_m&r | * |
| dell | emc_storage_monitoring_and_reporting | * |
EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability that could potentially be leveraged by malicious users to compromise the affected system.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-1188,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | elastic_cloud_storage | * |
Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in the REST API. An authenticated remote malicious user could potentially exploit this vulnerability to read certain system files in the server or cause denial of service by supplying specially crafted Document Type Definitions (DTDs) in an XML request.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 8.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H | 2.8 | 5.2 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_data_protection_advisor | 6.5 |
| dell | emc_integrated_data_protection_appliance | 2.0 |
| dell | emc_data_protection_advisor | 6.3 |
| dell | emc_integrated_data_protection_appliance | 2.1 |
| dell | emc_data_protection_advisor | 6.2 |
| dell | emc_data_protection_advisor | 6.4 |
Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) component. User credentials are sent unencrypted to the remote AMQP service. An unauthenticated attacker in the same network collision domain, could potentially sniff the password from the network and use it to access the component using the privileges of the compromised user.
CVSS 2.0
Severity: LOW
Problem Type: CWE-319,CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_networker | 18.1.0.1 |
| dell | emc_networker | * |
Dell EMC iDRAC Service Module for all supported Linux and XenServer versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, when started, changes the default file permission of the hosts file of the host operating system (/etc/hosts) to world writable. A malicious low privileged operating system user or process could modify the host file and potentially redirect traffic from the intended destination to sites hosting malicious or unwanted content.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N | 2.8 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_idrac_service_module | 3.0.1 |
| dell | emc_idrac_service_module | 3.1.0 |
| dell | emc_idrac_service_module | 3.0.2 |
| dell | emc_idrac_service_module | 3.2.0 |
RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote attacker could use maliciously constructed ASN.1 data to potentially cause a Denial Of Service.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-190,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | security_service | 11.1.1.9.0 |
| oracle | core_rdbms | 19c |
| oracle | real_user_experience_insight | 13.3.1.0 |
| oracle | security_service | 12.1.3.0.0 |
| oracle | communications_ip_service_activator | 7.3.4 |
| oracle | application_testing_suite | 13.3.0.1 |
| oracle | enterprise_manager_ops_center | 12.3.3 |
| oracle | core_rdbms | 12.1.0.2 |
| oracle | goldengate_application_adapters | 12.3.2.1.0 |
| oracle | retail_predictive_application_server | 15.0.3 |
| oracle | core_rdbms | 18c |
| dell | bsafe | 4.1.6 |
| oracle | security_service | 12.2.1.2.0 |
| oracle | real_user_experience_insight | 13.2.3.1 |
| oracle | enterprise_manager_ops_center | 12.4.0 |
| oracle | communications_ip_service_activator | 7.4.0 |
| oracle | core_rdbms | 12.2.0.1 |
| oracle | retail_predictive_application_server | 16.0.3 |
| oracle | real_user_experience_insight | 13.1.2.1 |
| oracle | jd_edwards_enterpriseone_tools | 9.2 |
| oracle | timesten_in-memory_database | * |
| oracle | core_rdbms | 11.2.0.4 |
| oracle | communications_analytics | 12.1.1 |
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauthorized data by doing heap inspection.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 1.8 | 3.6 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-404,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | security_service | 11.1.1.9.0 |
| oracle | core_rdbms | 19c |
| oracle | real_user_experience_insight | 13.3.1.0 |
| oracle | security_service | 12.1.3.0.0 |
| oracle | application_testing_suite | 13.3.0.1 |
| oracle | enterprise_manager_ops_center | 12.3.3 |
| oracle | core_rdbms | 12.1.0.2 |
| oracle | goldengate_application_adapters | 12.3.2.1.0 |
| oracle | retail_predictive_application_server | 15.0.3 |
| oracle | core_rdbms | 18c |
| oracle | retail_predictive_application_server | 16.0.3.0 |
| oracle | security_service | 12.2.1.3.0 |
| oracle | real_user_experience_insight | 13.2.3.1 |
| oracle | enterprise_manager_ops_center | 12.4.0 |
| oracle | communications_ip_service_activator | 7.4.0 |
| oracle | core_rdbms | 12.2.0.1 |
| oracle | communications_ip_service_activator | 7.3.0 |
| oracle | real_user_experience_insight | 13.1.2.1 |
| oracle | jd_edwards_enterpriseone_tools | 9.2 |
| oracle | timesten_in-memory_database | * |
| dell | bsafe | * |
| oracle | core_rdbms | 11.2.0.4 |
| oracle | communications_analytics | 12.1.1 |
RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would exhaust the stack, potentially causing a Denial Of Service.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H | 2.8 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-400,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | security_service | 11.1.1.9.0 |
| oracle | core_rdbms | 19c |
| oracle | real_user_experience_insight | 13.3.1.0 |
| oracle | enterprise_manager_ops_center | 12.3.3 |
| oracle | core_rdbms | 12.1.0.2 |
| oracle | retail_predictive_application_server | 16.0.3.0 |
| oracle | communications_ip_service_activator | 7.4.0 |
| oracle | core_rdbms | 12.2.0.1 |
| oracle | core_rdbms | 11.2.0.4 |
| oracle | security_service | 12.1.3.0.0 |
| oracle | application_testing_suite | 13.3.0.1 |
| oracle | goldengate_application_adapters | 12.3.2.1.0 |
| oracle | retail_predictive_application_server | 15.0.3 |
| oracle | core_rdbms | 18c |
| oracle | security_service | 12.2.1.3.0 |
| oracle | real_user_experience_insight | 13.2.3.1 |
| oracle | enterprise_manager_ops_center | 12.4.0 |
| oracle | communications_ip_service_activator | 7.3.0 |
| oracle | real_user_experience_insight | 13.1.2.1 |
| oracle | jd_edwards_enterpriseone_tools | 9.2 |
| oracle | timesten_in-memory_database | * |
| dell | bsafe_crypto-c | * |
| dell | bsafe | * |
| oracle | communications_analytics | 12.1.1 |
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N | 2.2 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | security_service | 11.1.1.9.0 |
| oracle | core_rdbms | 19c |
| oracle | real_user_experience_insight | 13.3.1.0 |
| oracle | security_service | 12.1.3.0.0 |
| oracle | application_testing_suite | 13.3.0.1 |
| oracle | enterprise_manager_ops_center | 12.3.3 |
| oracle | core_rdbms | 12.1.0.2 |
| oracle | goldengate_application_adapters | 12.3.2.1.0 |
| oracle | retail_predictive_application_server | 15.0.3 |
| oracle | core_rdbms | 18c |
| oracle | retail_predictive_application_server | 16.0.3.0 |
| oracle | security_service | 12.2.1.3.0 |
| oracle | real_user_experience_insight | 13.2.3.1 |
| oracle | enterprise_manager_ops_center | 12.4.0 |
| oracle | communications_ip_service_activator | 7.4.0 |
| oracle | core_rdbms | 12.2.0.1 |
| oracle | communications_ip_service_activator | 7.3.0 |
| oracle | real_user_experience_insight | 13.1.2.1 |
| oracle | jd_edwards_enterpriseone_tools | 9.2 |
| oracle | timesten_in-memory_database | * |
| dell | bsafe | * |
| oracle | core_rdbms | 11.2.0.4 |
| oracle | communications_analytics | 12.1.1 |
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result in such issue.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-125,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | security_service | 11.1.1.9.0 |
| oracle | core_rdbms | 19c |
| oracle | real_user_experience_insight | 13.3.1.0 |
| oracle | enterprise_manager_ops_center | 12.3.3 |
| oracle | core_rdbms | 12.1.0.2 |
| oracle | retail_predictive_application_server | 16.0.3.0 |
| oracle | communications_ip_service_activator | 7.4.0 |
| oracle | core_rdbms | 12.2.0.1 |
| oracle | core_rdbms | 11.2.0.4 |
| oracle | security_service | 12.1.3.0.0 |
| oracle | application_testing_suite | 13.3.0.1 |
| oracle | goldengate_application_adapters | 12.3.2.1.0 |
| oracle | retail_predictive_application_server | 15.0.3 |
| oracle | core_rdbms | 18c |
| oracle | security_service | 12.2.1.3.0 |
| oracle | real_user_experience_insight | 13.2.3.1 |
| oracle | enterprise_manager_ops_center | 12.4.0 |
| oracle | communications_ip_service_activator | 7.3.0 |
| oracle | real_user_experience_insight | 13.1.2.1 |
| oracle | jd_edwards_enterpriseone_tools | 9.2 |
| oracle | timesten_in-memory_database | * |
| dell | bsafe_crypto-c | * |
| dell | bsafe | * |
| oracle | communications_analytics | 12.1.1 |
Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with default passwords. These accounts have limited privileges and can access certain system files only. A malicious user with the knowledge of the default passwords may potentially log in to the system and gain read and write access to certain system files.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_integrated_data_protection_appliance | * |
Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multiple services incorrectly by specifying the paths to the service executables without quotes. This could potentially allow a low-privileged local user to execute arbitrary executables with elevated privileges.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-428,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | wyse_management_suite | * |
Dell EMC Unity OE versions 4.3.0.x and 4.3.1.x and UnityVSA OE versions 4.3.0.x and 4.3.1.x contains an Incorrect File Permissions vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability to alter multiple library files in service tools that might result in arbitrary code execution with elevated privileges. No user file systems are directly affected by this vulnerability.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_unity_operating_environment | * |
| dell | emc_unityvsa_operating_environment | * |
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain a Remote Code Execution vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to execute arbitrary commands on the server.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| vmware | vsphere_data_protection | 6.0.5 |
| vmware | vsphere_data_protection | 6.0.6 |
| dell | emc_avamar | 7.5.1 |
| vmware | vsphere_data_protection | 6.1.1 |
| vmware | vsphere_data_protection | 6.1.5 |
| vmware | vsphere_data_protection | 6.0.1 |
| vmware | vsphere_data_protection | 6.0.3 |
| dell | emc_avamar | 7.5.0 |
| dell | emc_avamar | 7.3.1 |
| dell | emc_avamar | 18.1 |
| vmware | vsphere_data_protection | 6.0.7 |
| dell | emc_integrated_data_protection_appliance | 2.1 |
| vmware | vsphere_data_protection | 6.1.9 |
| vmware | vsphere_data_protection | 6.1.3 |
| vmware | vsphere_data_protection | 6.1.2 |
| vmware | vsphere_data_protection | 6.1.7 |
| dell | emc_avamar | 7.4.0 |
| dell | emc_integrated_data_protection_appliance | 2.2 |
| dell | emc_avamar | 7.2.0 |
| vmware | vsphere_data_protection | 6.1.6 |
| vmware | vsphere_data_protection | 6.1.0 |
| vmware | vsphere_data_protection | 6.0.4 |
| dell | emc_integrated_data_protection_appliance | 2.0 |
| vmware | vsphere_data_protection | 6.0.8 |
| vmware | vsphere_data_protection | 6.0.0 |
| dell | emc_avamar | 7.4.1 |
| dell | emc_avamar | 7.2.1 |
| vmware | vsphere_data_protection | 6.1.8 |
| vmware | vsphere_data_protection | 6.1.4 |
| vmware | vsphere_data_protection | 6.0.2 |
| dell | emc_avamar | 7.3.0 |
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phishing attacks that cause users to unknowingly visit malicious sites.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| vmware | vsphere_data_protection | 6.0.5 |
| vmware | vsphere_data_protection | 6.0.6 |
| dell | emc_avamar | 7.5.1 |
| vmware | vsphere_data_protection | 6.1.1 |
| vmware | vsphere_data_protection | 6.1.5 |
| vmware | vsphere_data_protection | 6.0.1 |
| vmware | vsphere_data_protection | 6.0.3 |
| dell | emc_avamar | 7.5.0 |
| dell | emc_avamar | 7.3.1 |
| dell | emc_avamar | 18.1 |
| vmware | vsphere_data_protection | 6.0.7 |
| dell | emc_integrated_data_protection_appliance | 2.1 |
| vmware | vsphere_data_protection | 6.1.9 |
| vmware | vsphere_data_protection | 6.1.3 |
| vmware | vsphere_data_protection | 6.1.2 |
| vmware | vsphere_data_protection | 6.1.7 |
| dell | emc_avamar | 7.4.0 |
| dell | emc_integrated_data_protection_appliance | 2.2 |
| dell | emc_avamar | 7.2.0 |
| vmware | vsphere_data_protection | 6.1.6 |
| vmware | vsphere_data_protection | 6.1.0 |
| vmware | vsphere_data_protection | 6.0.4 |
| dell | emc_integrated_data_protection_appliance | 2.0 |
| vmware | vsphere_data_protection | 6.0.8 |
| vmware | vsphere_data_protection | 6.0.0 |
| dell | emc_avamar | 7.4.1 |
| dell | emc_avamar | 7.2.1 |
| vmware | vsphere_data_protection | 6.1.8 |
| vmware | vsphere_data_protection | 6.1.4 |
| vmware | vsphere_data_protection | 6.0.2 |
| dell | emc_avamar | 7.3.0 |
RSA BSAFE SSL-J versions prior to 6.2.4 contain a Heap Inspection vulnerability that could allow an attacker with physical access to the system to recover sensitive key material.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 4.6 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.9 | 3.6 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-459,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_ssl-j | * |
RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N | 2.2 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_ssl-j | * |
RSA BSAFE Crypto-J versions prior to 6.2.4 and RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during PKCS #1 unpadding operations, also known as a Bleichenbacher attack. A remote attacker may be able to recover a RSA key.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 5.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N | 2.2 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | bsafe_crypto-j | * |
| dell | rsa_bsafe_ssl-j | * |
Dell Digital Delivery versions prior to 3.5.1 contain a DLL Injection Vulnerability. A local authenticated malicious user with advance knowledge of the application workflow could potentially load and execute a malicious DLL with administrator privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-427,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | digital_delivery | * |
Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked in the Avamar Java management client package. The private key could potentially be used by an unauthenticated attacker on the same data-link layer to initiate a MITM attack on management console users.
CVSS 2.0
Severity: LOW
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| vmware | vsphere_data_protection | 6.0.5 |
| vmware | vsphere_data_protection | 6.0.6 |
| vmware | vsphere_data_protection | 6.1.1 |
| vmware | vsphere_data_protection | 6.1.5 |
| vmware | vsphere_data_protection | 6.0.1 |
| vmware | vsphere_data_protection | 6.0.3 |
| dell | emc_avamar | 7.3.1 |
| vmware | vsphere_data_protection | 6.0.7 |
| vmware | vsphere_data_protection | 6.1.9 |
| vmware | vsphere_data_protection | 6.1.3 |
| vmware | vsphere_data_protection | 6.1.2 |
| vmware | vsphere_data_protection | 6.1.7 |
| dell | emc_avamar | 7.4.0 |
| dell | emc_avamar | 7.2.0 |
| vmware | vsphere_data_protection | 6.1.6 |
| vmware | vsphere_data_protection | 6.1.0 |
| vmware | vsphere_data_protection | 6.0.4 |
| dell | emc_integrated_data_protection_appliance | 2.0 |
| vmware | vsphere_data_protection | 6.0.8 |
| vmware | vsphere_data_protection | 6.0.0 |
| dell | emc_avamar | 7.4.1 |
| dell | emc_avamar | 7.2.1 |
| vmware | vsphere_data_protection | 6.1.8 |
| vmware | vsphere_data_protection | 6.1.4 |
| vmware | vsphere_data_protection | 6.0.2 |
| dell | emc_avamar | 7.3.0 |
'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute arbitrary commands under root privilege.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| vmware | vsphere_data_protection | 6.0.5 |
| vmware | vsphere_data_protection | 6.0.6 |
| dell | emc_avamar | 7.5.1 |
| vmware | vsphere_data_protection | 6.1.1 |
| vmware | vsphere_data_protection | 6.1.5 |
| vmware | vsphere_data_protection | 6.0.1 |
| vmware | vsphere_data_protection | 6.0.3 |
| dell | emc_avamar | 7.5.0 |
| dell | emc_avamar | 7.3.1 |
| dell | emc_avamar | 18.1 |
| vmware | vsphere_data_protection | 6.0.7 |
| dell | emc_integrated_data_protection_appliance | 2.1 |
| vmware | vsphere_data_protection | 6.1.9 |
| vmware | vsphere_data_protection | 6.1.3 |
| vmware | vsphere_data_protection | 6.1.2 |
| vmware | vsphere_data_protection | 6.1.7 |
| dell | emc_avamar | 7.4.0 |
| dell | emc_integrated_data_protection_appliance | 2.2 |
| dell | emc_avamar | 7.2.0 |
| vmware | vsphere_data_protection | 6.1.6 |
| vmware | vsphere_data_protection | 6.1.0 |
| vmware | vsphere_data_protection | 6.0.4 |
| dell | emc_integrated_data_protection_appliance | 2.0 |
| vmware | vsphere_data_protection | 6.0.8 |
| vmware | vsphere_data_protection | 6.0.0 |
| dell | emc_avamar | 7.4.1 |
| dell | emc_avamar | 7.2.1 |
| vmware | vsphere_data_protection | 6.1.8 |
| vmware | vsphere_data_protection | 6.1.4 |
| vmware | vsphere_data_protection | 6.0.2 |
| dell | emc_avamar | 7.3.0 |
Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability. A remote authenticated malicious user could read from VPN configuration files on and potentially author a MITM attack on the VPN traffic.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_vplex_geosynchrony | * |
In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, Dell EMC VASA Provider Virtual Appliance versions prior to 8.4.0.512, Dell EMC SMIS versions prior to 8.4.0.6, Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4.0.347, Dell EMC VNX2 Operating Environment (OE) for File versions prior to 8.1.9.231, Dell EMC VNX2 Operating Environment (OE) for Block versions prior to 05.33.009.5.231, Dell EMC VNX1 Operating Environment (OE) for File versions prior to 7.1.82.0, Dell EMC VNX1 Operating Environment (OE) for Block versions prior to 05.32.000.5.225, Dell EMC VNXe3200 Operating Environment (OE) all versions, Dell EMC VNXe1600 Operating Environment (OE) versions prior to 3.1.9.9570228, Dell EMC VNXe 3100/3150/3300 Operating Environment (OE) all versions, Dell EMC ViPR SRM versions 3.7, 3.7.1, 3.7.2 (only if using Dell EMC Host Interface for Windows), Dell EMC ViPR SRM versions 4.0, 4.0.1, 4.0.2, 4.0.3 (only if using Dell EMC Host Interface for Windows), Dell EMC XtremIO versions 4.x, Dell EMC VMAX eNAS version 8.x, Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968, ECOM is affected by a XXE injection vulnerability due to the configuration of the XML parser shipped with the product. XXE Injection attack may occur when XML input containing a reference to an external entity (defined by the attacker) is processed by an affected XML parser. XXE Injection may allow attackers to gain unauthorized access to files containing sensitive information or may be used to cause denial-of-service.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-611,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_unisphere | * |
| dell | emc_vnxe_3150_operating_environment | - |
| dell | emc_vnxe1600_operating_environment | * |
| dell | emc_vipr_srm | 4.0.1 |
| dell | emc_vasa_provider_virtual_appliance | * |
| dell | emc_solutions_enabler_virtual_appliance | * |
| dell | emc_vnxe_3300__operating_environment | - |
| dell | emc_vipr_srm | 4.0.3 |
| dell | emc_vipr_srm | 4.0.2 |
| dell | emc_vmax_embedded_management | * |
| dell | emc_smis | * |
| dell | emc_vmax_enas | 8.0.1 |
| dell | emc_xtremio | 4.0.2 |
| dell | emc_vipr_srm | - |
| dell | emc_vipr_srm | 3.7.1 |
| dell | emc_vnxe3200_operating_environment | - |
| dell | emc_vnxe_3100_operating_environment | - |
| dell | emc_vipr_srm | 3.7.2 |
| dell | emc_vnx1_operating_environment | 7.1.82.0 |
| dell | emc_xtremio | 4.0 |
| dell | emc_unity_operating_environment | * |
| dell | emc_vipr_srm | 4.0 |
| dell | emc_vipr_srm | 3.7 |
| dell | emc_vnx1_operating_environment | 05.32.000.5.225 |
| dell | emc_vmax_enas | 8.0 |
| dell | emc_vnx2_operating_environment | * |
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versions prior to 5.0.1.3. Command injection vulnerability in Boxmgmt CLI may allow a malicious user with boxmgmt privileges to bypass Boxmgmt CLI and run arbitrary commands with root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_recoverpoint_for_virtual_machines | * |
| dell | emc_recoverpoint | 5.1.0.0 |
| dell | emc_recoverpoint | * |
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versions prior to 5.0.1.3. Command injection vulnerability in Admin CLI may allow a malicious user with admin privileges to escape from the restricted shell to an interactive shell and run arbitrary commands with root privileges.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.7 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H | 0.8 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_recoverpoint_for_virtual_machines | * |
| dell | emc_recoverpoint | 5.1.0.0 |
| dell | emc_recoverpoint | * |
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Cluster description of the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_isilon | * |
| dell | emc_isilon | 7.1.1.11 |
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6 is affected by a cross-site scripting vulnerability in the Network Configuration page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_isilon | * |
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and versions 7.2.1.x is affected by a cross-site scripting vulnerability in the Authorization Providers page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_isilon | * |
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Antivirus Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_isilon | * |
| dell | emc_isilon | 7.1.1.11 |
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Job Operations Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_isilon | * |
| dell | emc_isilon | 7.1.1.11 |
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the NDMP Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_isilon | * |
| dell | emc_isilon | 7.1.1.11 |
In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, the tcpdump binary, being run with sudo, may potentially be used by compadmin to execute arbitrary code with root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_isilon_onefs | * |
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a path traversal vulnerability in the isi_phone_home tool. A malicious compadmin may potentially exploit this vulnerability to execute arbitrary code with root privileges.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_isilon_onefs | * |
| dell | emc_isilon_onefs | 7.1.1.11 |
Dell EMC ScaleIO, versions prior to 2.5, do not properly handle some packet data in the MDM service. As a result, a remote attacker could potentially send specifically crafted packet data to the MDM service causing it to crash.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_scaleio | * |
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_idrac8 | * |
| dell | emc_idrac7 | * |
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI parser which could be used to obtain specific sensitive data without authentication. A remote unauthenticated attacker may be able to read configuration settings from the iDRAC by querying specific URI strings.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_idrac8 | * |
| dell | emc_idrac7 | * |
The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as root on the affected iDRAC system.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | idrac6_modular | * |
| dell | idrac6_monolithic | * |
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 and 8.1.0.2 is affected by a cross-site request forgery vulnerability. A malicious user may potentially exploit this vulnerability to send unauthorized requests to the server on behalf of authenticated users of the application.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_isilon_onefs | * |
| dell | emc_isilon_onefs | 7.1.1.11 |
| dell | emc_isilon_onefs | 8.1.0.2 |
Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after an upgrade from v1.1 to v1.2. Access to the management console can be achieved by someone with knowledge of the default password. If SupportAssist Enterprise is installed on a server running OpenManage Essentials (OME), the OmeAdapterUser user account is added as a member of the OmeAdministrators group for the OME. An unauthorized person with knowledge of the default password and access to the OME web console could potentially use this account to gain access to the affected installation of OME with OmeAdministrators privileges. This is fixed in version 1.2.1.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_supportassist_enterprise | 1.1 |
An arbitrary file upload vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.21, Dell EMC VASA Virtual Appliance versions prior to 8.4.0.514, and Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier). A remote authenticated malicious user may potentially upload arbitrary maliciously crafted files in any location on the web server. By chaining this vulnerability with CVE-2018-1216, the attacker may use the default account to exploit this vulnerability.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-434,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_vasa_virtual_appliance | * |
| dell | emc_unisphere_for_vmax_virtual_appliance | * |
| dell | emc_vmax_embedded_management | * |
| dell | emc_solutions_enabler_virtual_appliance | * |
A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.21, Dell EMC VASA Virtual Appliance versions prior to 8.4.0.514, and Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier). They contain an undocumented default account (smc) with a hard-coded password that may be used with certain web servlets. A remote attacker with the knowledge of the hard-coded password and the message format may use vulnerable servlets to gain unauthorized access to the system. Note: This account cannot be used to log in via the web user interface.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_vasa_virtual_appliance | * |
| dell | emc_unisphere_for_vmax_virtual_appliance | * |
| dell | emc_vmax_embedded_management | * |
| dell | emc_solutions_enabler_virtual_appliance | * |
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials. The LDLS credentials are used to connect to Dell EMC Online Support. If the LDLS configuration was changed to an invalid configuration, then Avamar Installation Manager may not be able to connect to Dell EMC Online Support web site successfully. The remote unauthenticated attacker can also read and use the credentials to login to Dell EMC Online Support, impersonating the AVI service actions using those credentials.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-862,NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_integrated_data_protection_appliance | 2.0 |
| dell | emc_integrated_data_protection_appliance | 2.1 |
| dell | emc_avamar | 7.4.1 |
| dell | emc_avamar | 7.5.0 |
| dell | emc_avamar | 7.3.1 |
In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer overflow condition when handling certain messages. A remote unauthenticated attacker could potentially exploit this vulnerability to cause a denial of service to the users of NetWorker systems.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_networker | * |
Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LIA). This component is deployed on every server in the ScaleIO cluster and is used for central management of ScaleIO nodes. A remote malicious user, having network access to LIA, could potentially exploit this vulnerability to launch brute force guessing of user names and passwords of user accounts on the LIA.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_scaleio | * |
Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA). This component is used for central management of ScaleIO deployment and uses shell commands for certain actions. A remote malicious user, with network access to LIA and knowledge of the LIA administrative password, could potentially exploit this vulnerability to run arbitrary commands as root on the systems where LIAs are installed.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_scaleio | * |
Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injection vulnerabilities. A remote application admin user could potentially exploit the vulnerabilities to execute arbitrary OS commands as system root on the system where Dell EMC Unity is installed.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_unity_operating_environment | * |
| dell | emc_unityvsa_operating_environment | * |
Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.21.21, contain a weak CGI session ID vulnerability. The sessions invoked via CGI binaries use 96-bit numeric-only session ID values, which makes it easier for remote attackers to perform bruteforce session guessing attacks.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-358,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | idrac7_firmware | * |
| dell | idrac6_firmware | * |
| dell | idrac8_firmware | * |
| dell | idrac9_firmware | * |
Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP agent. A remote authenticated malicious iDRAC user with configuration privileges could potentially exploit this vulnerability to execute arbitrary commands on the iDRAC where SNMP alerting is enabled.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | idrac7_firmware | * |
| dell | idrac8_firmware | * |
| dell | idrac9_firmware | * |
Dell EMC Unity and UnityVSA contains reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by the web browser.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_unity_operating_environment | * |
| dell | emc_unityvsa_operating_environment | * |
Dell EMC iDRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to iDRAC web server for certain URLs. A man-in-the-middle attacker could use this vulnerability to strip the SSL/TLS protection from a connection between a client and a server.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | idrac9_firmware | * |
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could potentially exploit this vulnerability to read files in NAS server by directly interacting with certain APIs of Unity OE, bypassing Role-Based Authorization control implemented only in Unisphere GUI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-863,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_unityvsa | * |
| dell | emc_unity_firmware | * |
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary web URLs by tricking the victim user to click on a maliciously crafted Unisphere URL. Attacker could potentially phish information, including Unisphere users' credentials, from the victim once they are redirected.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_unityvsa | * |
| dell | emc_unity_firmware | * |
On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware Version V4.02.15(2335dn MFP) 11-22-2010, the admin interface allows an authenticated attacker to retrieve the configured SMTP or LDAP password by viewing the HTML source code of the Email Settings webpage. In some cases, authentication can be achieved with the blank default password for the admin account. NOTE: the vendor indicates that this is an "End Of Support Life" product.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-521,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | 2335dn_engine_firmware | 1.10.65 |
| dell | 2335dn_network_firmware | v4.02.15(2335dn_mfp)_11-22-2010 |
| dell | 2335dn_printer_firmware | 2.70.05.02 |
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive data including executed commands to generate authentication tokens which may prove useful to an attacker for crafting malicious authentication tokens for querying the application and subsequent attacks.
CVSS 2.0
Severity: LOW
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_secure_remote_services | * |
On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that device. This allows for users to bypass any existing policy for password length and potentially create insecure password on their device. This value is defined during the installation of the "Encryption Management Agent" or "EMAgent" application. There are no other known values modified.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-521,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | endpoint_security_suite_enterprise | * |
| dell | encryption | * |
The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfiguration in the /etc/sudoers file.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-863,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | openmanage_network_manager | * |
Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due to insecure default configuration setting for the embedded MySQL database.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | openmanage_network_manager | * |
RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series) contain a key management error issue. A malicious TLS server could potentially cause a Denial Of Service (DoS) on TLS clients during the handshake when a very large prime value is sent to the TLS client, and an Ephemeral or Anonymous Diffie-Hellman cipher suite (DHE or ADH) is used.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| oracle | security_service | 11.1.1.9.0 |
| oracle | core_rdbms | 19c |
| oracle | real_user_experience_insight | 13.3.1.0 |
| oracle | security_service | 12.1.3.0.0 |
| oracle | application_testing_suite | 13.3.0.1 |
| oracle | enterprise_manager_ops_center | 12.3.3 |
| oracle | core_rdbms | 12.1.0.2 |
| oracle | goldengate_application_adapters | 12.3.2.1.0 |
| oracle | retail_predictive_application_server | 15.0.3 |
| oracle | core_rdbms | 18c |
| oracle | retail_predictive_application_server | 16.0.3.0 |
| oracle | security_service | 12.2.1.3.0 |
| oracle | real_user_experience_insight | 13.2.3.1 |
| oracle | enterprise_manager_ops_center | 12.4.0 |
| oracle | communications_ip_service_activator | 7.4.0 |
| oracle | core_rdbms | 12.2.0.1 |
| oracle | communications_ip_service_activator | 7.3.0 |
| oracle | real_user_experience_insight | 13.1.2.1 |
| oracle | jd_edwards_enterpriseone_tools | 9.2 |
| oracle | timesten_in-memory_database | * |
| dell | bsafe | * |
| oracle | core_rdbms | 11.2.0.4 |
| oracle | communications_analytics | 12.1.1 |
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an uncontrolled resource consumption vulnerability. A malicious boxmgmt user may potentially be able to consume large amount of CPU bandwidth to make the system slow or to determine the existence of any system file via Boxmgmt CLI.
CVSS 2.0
Severity: LOW
Problem Type: CWE-400,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_recoverpoint_for_virtual_machines | * |
| dell | emc_recoverpoint | * |
Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | data_protection_|_encryption | * |
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privilege escalation vulnerability. An authenticated malicious iDRAC user with operator privileges could potentially exploit a permissions check flaw in the Redfish interface to gain administrator access.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-863,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | idrac7_firmware | * |
| dell | idrac8_firmware | * |
| dell | idrac9_firmware | * |
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability to get access to the u-boot shell.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | idrac7_firmware | * |
| dell | idrac8_firmware | * |
Dell OS10 versions prior to 10.4.2.1 contain a vulnerability caused by lack of proper input validation on the command-line interface (CLI).
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | networking_os10 | * |
The Dell Wyse Password Encoder in ThinLinux2 versions prior to 2.1.0.01 contain a Hard-coded Cryptographic Key vulnerability. An unauthenticated remote attacker could reverse engineer the cryptographic system used in the Dell Wyse Password Encoder to discover the hard coded private key and decrypt locally stored cipher text.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | wyse_thinlinux | * |
Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certificate authority during TLS handshake. Use of an invalid or malicious certificate could potentially allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-295,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | networking_os10 | * |
VNX Control Station in Dell EMC VNX2 OE for File versions prior to 8.1.9.236 contains OS command injection vulnerability. Due to inadequate restriction configured in sudores, a local authenticated malicious user could potentially execute arbitrary OS commands as root by exploiting this vulnerability.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | emc_vnx2_firmware | * |
Dell WES Wyse Device Agent versions prior to 14.1.2.9 and Dell Wyse ThinLinux HAgent versions prior to 5.4.55 00.10 contain a buffer overflow vulnerability. An unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code on the system with privileges of the FTP client by sending specially crafted input data to the affected system. The FTP code that contained the vulnerability has been removed.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| dell | wyse_thinlinux_hagent | * |
| dell | windows_embedded_standard_wyse_device_agent | * |