Dell Security Vulnerabilities (CVEs)
Track 469 security vulnerabilities affecting Dell products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability that allows a local high-privileged atta...
Jul 2, 2024Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 use broken or risky cryptographic algorithms, allowing unprivileged network attackers to potent...
Jul 2, 2024Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability that allows a local high-privilege attac...
Jul 2, 2024This CVE describes a session hijacking vulnerability in iDRAC9's IPMI interface that allows remote attackers to take over authenticated sessions. Succ...
Jun 29, 2024Dell PowerProtect DD management console contains a relative path traversal vulnerability that allows authenticated high-privilege attackers to send un...
Jun 26, 2024Dell PowerProtect DD versions before 8.0 contain an OS command injection vulnerability in an admin operation. A remote attacker with low privileges ca...
Jun 26, 2024Dell PowerProtect Data Domain systems using weak cryptographic algorithms are vulnerable to man-in-the-middle attacks. Remote unauthenticated attacker...
Jun 26, 2024Dell PowerProtect DD versions contain an out-of-bounds write vulnerability that allows low-privileged remote attackers to execute arbitrary code. This...
Jun 26, 2024This SSRF vulnerability in Dell PowerProtect DD allows remote attackers with high privileges to make the server send requests to internal systems, pot...
Jun 26, 2024Dell PowerEdge Server BIOS contains a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability that allows a local low-privileged attacker to p...
Jun 25, 2024Dell Secure Connect Gateway (SCG) versions before 5.24.00.00 have an improper access control vulnerability in an internal update REST API. A remote lo...
Jun 13, 2024CVE-2024-37131 is an overly permissive Cross-Origin Resource Policy (CORP) vulnerability in Dell Secure Connect Gateway Policy Manager. This allows re...
Jun 13, 2024Dell Secure Connect Gateway (SCG) versions before 5.24.00.00 have an improper access control vulnerability in an internal REST API. A remote low-privi...
Jun 13, 2024Dell Secure Connect Gateway (SCG) versions before 5.24.00.00 have an improper access control vulnerability in an internal maintenance REST API. If an ...
Jun 13, 2024Dell Client Platform BIOS contains an improper input validation vulnerability in an externally developed component. A high-privileged attacker with lo...
Jun 13, 2024Dell Client Platform BIOS contains an improper input validation vulnerability in an externally developed component. A high-privileged attacker with lo...
Jun 13, 2024Dell Common Event Enabler versions 8.9.10.0 and earlier contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attack...
Jun 12, 2024Dell Client BIOS contains an out-of-bounds write vulnerability that allows a local authenticated malicious user with admin privileges to potentially c...
Jun 12, 2024Dell OpenManage Server Administrator (OMSA) versions 11.0.1.0 and prior contain a local privilege escalation vulnerability via XSL hijacking. A local ...
Jun 11, 2024Dell BIOS contains a missing integrity check vulnerability that allows attackers with physical access to bypass security mechanisms and execute arbitr...
Jun 7, 2024Dell Data Protection Advisor versions 19.9 contain an inadequate encryption strength vulnerability (CWE-326). A low-privileged attacker with remote ac...
May 29, 2024Dell BIOS contains an improper input validation vulnerability that allows a local authenticated malicious user with admin privileges to execute arbitr...
May 17, 2024Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contain a resource allocation vulnerability where an attacker can cause denial of service by exha...
May 14, 2024This CVE describes a privilege escalation vulnerability in Dell PowerScale OneFS where local high-privileged users can execute commands with unnecessa...
May 14, 2024Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contain a path traversal vulnerability where an attacker with local high privileges can control f...
May 14, 2024CVE-2024-24908 is a path traversal vulnerability in Dell PowerProtect DM5500 that allows authenticated high-privilege attackers to delete arbitrary fi...
May 8, 2024Dell OpenManage Enterprise versions 4.1.0 and older contain a cross-site scripting (XSS) vulnerability that allows high-privileged attackers with remo...
May 1, 2024Dell Repository Manager versions before 3.4.5 contain a path traversal vulnerability in the API module. A local attacker with low privileges can explo...
Apr 24, 2024Dell Alienware Command Center versions before 6.2.7.0 have a path traversal vulnerability where local attackers can place malicious files in the appli...
Apr 10, 2024Dell PowerScale OneFS contains a UNIX symbolic link following vulnerability that allows local high-privileged attackers to manipulate symbolic links t...
Mar 28, 2024Dell PowerScale OneFS versions 9.5.0.x through 9.7.0.x have an insufficient session expiration vulnerability that allows remote unauthenticated attack...
Mar 28, 2024Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x transmit sensitive information in cleartext, allowing a local low-privileged attacker to interc...
Mar 28, 2024Dell vApp Manager versions prior to 9.2.4.9 contain a command injection vulnerability (CWE-78) that allows authorized attackers to execute arbitrary c...
Mar 28, 2024Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x log sensitive information that could be accessed by local low-privileged users. This vulnerabil...
Mar 28, 2024Dell InsightIQ version 5.0 has an improper access control vulnerability that allows remote low-privileged attackers to gain unauthorized access to mon...
Mar 27, 2024Dell PowerScale OneFS versions 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability that allows remote unauthenticated attackers to p...
Mar 25, 2024A heap-based buffer overflow vulnerability in Dell PowerEdge Server BIOS allows local high-privileged attackers to write to unauthorized memory. This ...
Mar 19, 2024This vulnerability allows a local low-privileged attacker on affected Dell PowerEdge and Precision Rack servers to perform arbitrary writes to SMRAM (...
Mar 13, 2024A buffer overflow vulnerability in Dell Digital Delivery allows local low-privileged attackers to execute arbitrary code or escalate privileges. This ...
Mar 4, 2024Dell Display and Peripheral Manager for macOS contains an improper access control vulnerability that allows low-privileged users to modify files in th...
Mar 4, 2024CVE-2024-22426 is an unauthenticated remote OS command injection vulnerability in Dell RecoverPoint for Virtual Machines. An attacker can execute arbi...
Feb 16, 2024CVE-2023-39245 is an information disclosure vulnerability in DELL ESI for SAP LAMA's EHAC component that allows remote unauthenticated attackers to ea...
Feb 15, 2024Dell Networking Switches running vulnerable Enterprise SONiC versions contain an improper input validation vulnerability that allows remote unauthenti...
Feb 15, 2024Dell OS10 Networking Switches running 10.5.2.x and above contain a zeroMQ vulnerability when VLT (Virtual Link Trunking) is configured. Remote unauthe...
Feb 15, 2024This vulnerability in Dell SupportAssist allows locally authenticated users to escalate privileges and execute arbitrary code with Windows system-leve...
Feb 14, 2024This vulnerability in Dell SupportAssist for Home PCs allows local attackers to escalate privileges during first-time installations. Only users who pe...
Feb 14, 2024Dell PowerProtect Data Manager versions 19.15 and earlier contain an OS command injection vulnerability that allows remote authenticated high-privileg...
Feb 13, 2024This CVE describes an OS command injection vulnerability in Dell Unity's svc_dc utility that allows authenticated attackers to execute arbitrary comma...
Feb 12, 2024This CVE describes an OS command injection vulnerability in Dell Unity's svc_udoctor utility. Authenticated local attackers can execute arbitrary oper...
Feb 12, 2024This CVE describes an OS command injection vulnerability in Dell Unity's svc_nas utility that allows authenticated attackers to escape the restricted ...
Feb 12, 2024Why Monitor Dell Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 469+ known vulnerabilities affecting Dell products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Dell packages in under 60 seconds. No agents required - completely agentless scanning that works across Dell deployments.
Free vulnerability database: Access detailed information about every Dell CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Dell CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions