Dell Security Vulnerabilities (CVEs)
Track 469 security vulnerabilities affecting Dell products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
Dell RecoverPoint for Virtual Machines 6.0.x has an authentication rate limiting vulnerability that allows attackers to perform brute-force or diction...
Dec 13, 2024This vulnerability allows a high-privileged attacker with local access to execute arbitrary code on Dell systems due to improper input validation in a...
Dec 12, 2024Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) race condition vulnerability that allows a low-privileged attacker with local a...
Dec 11, 2024Dell VxVerify versions before x.40.405 store passwords in plain text within shell wrapper files. A local high-privileged attacker can read these crede...
Dec 11, 2024Dell Client Platform Firmware Update Utility has an Improper Link Resolution vulnerability (CWE-61) that allows a high-privileged attacker with local ...
Dec 11, 2024This SQL injection vulnerability in Dell Avamar allows unauthenticated remote attackers to execute arbitrary commands on affected systems. It affects ...
Dec 10, 2024This SQL injection vulnerability in Dell Avamar allows low-privileged remote attackers to execute arbitrary SQL commands, potentially leading to scrip...
Dec 10, 2024This CVE describes an Improper Link Resolution Before File Access vulnerability in multiple Dell PowerFlex and related products. An unauthenticated at...
Dec 10, 2024Dell OpenManage Server Administrator (OMSA) versions 11.0.1.0 and prior contain an improper input validation vulnerability that allows remote low-priv...
Dec 9, 2024Dell Power Manager versions before 3.17 have an improper access control vulnerability that allows local low-privileged attackers to execute arbitrary ...
Dec 9, 2024Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.x contain an incorrect argument specification vulnerability that allows remote low-privileged leg...
Dec 9, 2024Dell PowerScale OneFS versions 9.5.0.x through 9.8.0.x contain an uncontrolled resource consumption vulnerability. A low-privilege remote attacker cou...
Dec 9, 2024Dell NetWorker versions 19.10 contain an authorization bypass vulnerability where an unauthenticated attacker can manipulate user-controlled keys to a...
Dec 3, 2024Dell NetWorker Management Console versions 19.11 contain an improper cryptographic signature verification vulnerability. An unauthenticated attacker w...
Dec 3, 2024Dell Wyse Management Suite versions 4.4 and earlier contain an authentication bypass vulnerability where attackers can replay captured authentication ...
Nov 26, 2024Dell Wyse Management Suite versions 4.4 and earlier have a vulnerability where attackers with high privileges and remote access can bypass protection ...
Nov 26, 2024This vulnerability allows a high-privileged attacker with local access to exploit shared microarchitectural structures during transient execution, pot...
Nov 22, 2024This CVE describes a command injection vulnerability in Dell SmartFabric OS10 Software that allows a low-privileged attacker with local access to exec...
Nov 12, 2024Dell SmartFabric OS10 Software contains a command injection vulnerability that allows low-privileged attackers with local access to execute arbitrary ...
Nov 12, 2024Dell SmartFabric OS10 Software contains a privilege escalation vulnerability where low-privileged local attackers can execute commands with elevated p...
Nov 12, 2024This critical vulnerability in Dell Enterprise SONiC OS allows authenticated high-privileged attackers to execute arbitrary operating system commands ...
Nov 8, 2024Dell Enterprise SONiC OS versions 4.1.x and 4.2.x contain a missing critical step in authentication that allows unauthenticated remote attackers to by...
Nov 8, 2024Dell PowerProtect Data Domain has a local privilege escalation vulnerability where authenticated low-privileged users can execute unauthorized command...
Nov 8, 2024Dell Data Lakehouse versions 1.0.0.0 and 1.1.0 contain an improper access control vulnerability that allows unauthenticated attackers on adjacent netw...
Oct 25, 2024Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS versions 5.24 has an improper certificate validation vulnerability. A low-privileged attacker wi...
Oct 18, 2024Dell Secure Connect Gateway 5.24 has incorrect default file permissions that allow local low-privileged attackers to access the file system. This coul...
Oct 18, 2024Dell OpenManage Enterprise versions 4.1 and earlier contain a code injection vulnerability that allows authenticated attackers with low privileges to ...
Oct 17, 2024This CVE describes a command injection vulnerability in Dell SmartFabric OS10 Software that allows low-privileged remote attackers to execute arbitrar...
Sep 26, 2024Dell SmartFabric OS10 Software contains an uncontrolled resource consumption vulnerability that allows remote unauthenticated attackers to cause denia...
Sep 26, 2024CVE-2024-39583 is a cryptographic vulnerability in Dell PowerScale InsightIQ versions 5.0 through 5.1 that allows unauthenticated remote attackers to ...
Sep 10, 2024Dell PowerScale InsightIQ version 5.1 contains an improper privilege management vulnerability that allows a high-privileged attacker with local access...
Sep 10, 2024CVE-2024-39581 is a directory traversal vulnerability in Dell PowerScale InsightIQ versions 5.0 through 5.1 that allows unauthenticated remote attacke...
Sep 10, 2024Dell ThinOS versions 2402 and 2405 contain a command injection vulnerability that allows unauthenticated attackers with physical access to execute arb...
Sep 10, 2024This vulnerability allows a low-privileged attacker with remote access to execute arbitrary commands on Dell SmartFabric OS10 networking devices throu...
Sep 6, 2024Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A local high-privileged attacker could...
Aug 31, 2024Dell Client Platform BIOS contains a vulnerability where default cryptographic keys are used, allowing a high-privileged attacker with local access to...
Aug 28, 2024CVE-2023-22576 is a local privilege escalation vulnerability in Dell Repository Manager versions 3.4.2 and earlier. A local low-privileged attacker ca...
Aug 21, 2024Dell SupportAssist for Home PCs Installer version 4.0.3 contains a local privilege escalation vulnerability where a low-privileged authenticated attac...
Aug 21, 2024Dell BIOS contains an improper input validation vulnerability in an externally developed component that allows a high-privileged attacker with local a...
Aug 14, 2024Dell Command | Update, Dell Update, and Alienware Update UWP applications contain an exposed dangerous method vulnerability in versions prior to 5.4. ...
Aug 6, 2024CVE-2024-38490 is an out-of-bounds write vulnerability in Dell iDRAC Service Module versions 5.3.0.0 and earlier. A privileged local attacker could ex...
Aug 1, 2024CVE-2024-25948 is an out-of-bounds write vulnerability in Dell iDRAC Service Module versions 5.3.0.0 and earlier. A privileged local attacker could ex...
Aug 1, 2024Dell iDRAC Service Module versions 5.3.0.0 and earlier contain an out-of-bounds read vulnerability that could allow a privileged local attacker to exe...
Aug 1, 2024Dell Inventory Collector versions before 12.3.0.6 contain a path traversal vulnerability that allows local authenticated users to write files to arbit...
Jul 31, 2024Dell Peripheral Manager versions before 1.7.6 have a DLL hijacking vulnerability where attackers can place malicious DLLs in locations the software se...
Jul 31, 2024Dell Peripheral Manager versions before 1.7.6 have a DLL hijacking vulnerability where attackers can place malicious DLLs in locations the application...
Jul 31, 2024This vulnerability allows an unauthenticated attacker with local access to read memory outside intended bounds in Dell BSAFE cryptographic libraries. ...
Jul 31, 2024Dell ECS versions before 3.8.1 contain a privilege elevation vulnerability in user management. A remote attacker with high privileges could exploit th...
Jul 18, 2024This vulnerability allows a local authenticated user with high privileges to perform an out-of-bounds write in Dell Edge Gateway BIOS, potentially lea...
Jul 10, 2024Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high-privileged attacker with local ...
Jul 2, 2024Why Monitor Dell Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 469+ known vulnerabilities affecting Dell products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Dell packages in under 60 seconds. No agents required - completely agentless scanning that works across Dell deployments.
Free vulnerability database: Access detailed information about every Dell CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Dell CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions