Dell Security Vulnerabilities (CVEs)
Track 470 security vulnerabilities affecting Dell products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
Dell VNX2 file storage systems running version 8.1.21.266 or earlier contain an unauthenticated remote code execution vulnerability. Attackers can exe...
Apr 8, 2022Dell PowerScale OneFS versions 8.2.2 through 9.3.x contain a predictable file name vulnerability that allows unprivileged network attackers to potenti...
Apr 8, 2022Dell PowerScale OneFS versions 8.2.x through 9.2.x contain weak cryptographic algorithms that could allow a remote attacker without privileges to gain...
Apr 8, 2022Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability that allows authenticated admin users to uploa...
Apr 1, 2022Dell BIOS contains an improper input validation vulnerability in System Management Mode (SMM). A local authenticated attacker can exploit this via Sys...
Mar 11, 2022CVE-2022-24421 is a BIOS vulnerability in Dell systems where improper input validation allows a local authenticated attacker to execute arbitrary code...
Mar 11, 2022This CVE describes an improper input validation vulnerability in Dell BIOS that allows a local authenticated malicious user to exploit System Manageme...
Mar 11, 2022This vulnerability allows a remote attacker with standard JEA (Just Enough Administration) credentials to escalate privileges and potentially take ove...
Feb 9, 2022Dell VNX2 OE for File versions 8.1.21.266 and earlier contain a sensitive information disclosure vulnerability that allows local malicious users to re...
Jan 25, 2022CVE-2021-36294 is an authentication bypass vulnerability in Dell VNX2 OE for File versions 8.1.21.266 and earlier. A remote attacker can forge a cooki...
Jan 25, 2022Dell VNX2 OE for File versions 8.1.21.266 and earlier contain an authenticated remote code execution vulnerability. A malicious user with valid creden...
Jan 25, 2022This CVE describes a stack-based buffer overflow vulnerability in Dell iDRAC9 and iDRAC8 remote management controllers. An authenticated attacker with...
Jan 25, 2022Dell BIOS contains an improper input validation vulnerability that allows a local authenticated malicious user to exploit System Management Interrupt ...
Jan 24, 2022Dell EMC System Update versions 1.9.2 and earlier store user credentials insecurely, allowing local attackers with user privileges to read passwords. ...
Jan 24, 2022Dell EMC AppSync versions 3.9 to 4.3 transmit sensitive session information via GET request query strings, which can be intercepted by adjacent attack...
Jan 21, 2022Dell EMC AppSync versions 3.9 to 4.3 have an authentication rate limiting vulnerability that allows adjacent unauthenticated attackers to perform pass...
Jan 21, 2022CVE-2021-36336 is a critical deserialization vulnerability in Wyse Management Suite that allows unauthenticated attackers to execute arbitrary code on...
Dec 21, 2021Dell PowerPath Management Appliance versions 2.6 through 3.2 use hard-coded cryptographic keys, allowing local high-privileged malicious users to decr...
Dec 21, 2021CVE-2021-36328 is a SQL injection vulnerability in Dell EMC Streaming Data Platform that allows remote attackers to execute arbitrary SQL commands. Th...
Nov 30, 2021Dell EMC Streaming Data Platform versions before 1.3 contain an insufficient session expiration vulnerability that allows remote unauthenticated attac...
Nov 30, 2021Dell EMC CloudLink versions 7.1 and earlier contain hard-coded credentials that allow remote attackers with knowledge of these credentials to gain una...
Nov 23, 2021Dell EMC CloudLink versions 7.1 and earlier contain an arbitrary file creation vulnerability that allows remote unauthenticated attackers to create ar...
Nov 23, 2021This SQL injection vulnerability in Dell iDRAC9 allows authenticated low-privilege users to execute arbitrary SQL commands. Attackers could potentiall...
Nov 23, 2021CVE-2021-36306 is an authentication bypass vulnerability in Dell Networking OS10's RESTCONF API that allows remote unauthenticated attackers to gain u...
Nov 20, 2021Dell Networking X-Series switches with firmware versions before 3.0.1.8 contain an authentication bypass vulnerability. Remote attackers can forge ses...
Nov 20, 2021Dell EMC Secure Connect Gateway (SCG) versions 5.00.00.10 and earlier contain a sensitive information disclosure vulnerability. A local malicious user...
Nov 20, 2021Dell EMC InsightIQ versions before 4.1.4 use weak cryptographic algorithms in SSH, allowing unauthenticated attackers to bypass authentication and gai...
Oct 1, 2021Dell BIOS contains an improper input validation vulnerability that allows a local authenticated attacker to execute arbitrary code in SMRAM via System...
Sep 28, 2021Dell SupportAssist Client Consumer versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability. Attackers can exploit NTFS symbolic li...
Sep 28, 2021Dell PowerScale OneFS versions 8.2.2 through 9.1.0.x have a vulnerability where sensitive data can be exposed through GET requests containing sensitiv...
Aug 16, 2021Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 expose sensitive information in log files. Local users with specific privileges (ISI_PR...
Aug 16, 2021Dell EMC PowerScale OneFS versions 8.2.x through 9.2.x contain an incorrect permission assignment vulnerability that allows users with SSH or console ...
Aug 16, 2021This vulnerability allows authenticated users with SSH or console login privileges on Dell PowerScale OneFS systems to elevate their privileges beyond...
Aug 10, 2021Dell EMC Data Protection Search and IDPA contain an information exposure vulnerability where sensitive user credentials are logged in plain text. A lo...
Aug 10, 2021This vulnerability allows a local authenticated malicious user to execute arbitrary code on systems running vulnerable versions of Dell Command | Upda...
Aug 9, 2021Dell OpenManage Enterprise versions before 3.6.1 have an improper authentication vulnerability that allows remote unauthenticated attackers to hijack ...
Aug 9, 2021CVE-2021-21585 is an OS command injection vulnerability in Dell OpenManage Enterprise's RACADM and IPMI tools. Remote authenticated users with high pr...
Aug 9, 2021Dell PowerScale OneFS versions 8.1.0 through 9.1.0 contain an incorrect user management vulnerability that allows CompAdmin users to elevate privilege...
Aug 3, 2021This vulnerability allows attackers to spoof their UID over NFS to gain write access to the admin home directory on affected Dell Isilon/PowerScale sy...
Jul 29, 2021Dell EMC iDRAC9 versions 4.40.00.00 through 4.40.10.00 contain an improper authentication vulnerability that allows remote unauthenticated attackers t...
Jul 29, 2021This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Dell EMC Avamar Server and Integrated Data Protection Applianc...
Jul 28, 2021This vulnerability allows a locally authenticated low-privileged user to load arbitrary DLLs through Dell SupportAssist, leading to privilege escalati...
Jul 22, 2021Dell EMC Repository Manager (DRM) version 3.2 stores proxy server passwords in plain text in a local database. This allows any authenticated local use...
Jul 19, 2021This CVE describes a SQL injection vulnerability in Dell EMC OpenManage Enterprise and OpenManage Enterprise-Modular management platforms. Remote auth...
Jul 19, 2021CVE-2020-5322 is a command injection vulnerability in Dell EMC OpenManage Enterprise-Modular (OME-M) that allows remote authenticated users with high ...
Jul 19, 2021Dell EMC Networking S4100 and S5200 Series Switches manufactured before February 2020 contain hardcoded administrative credentials. Remote attackers c...
Jul 19, 2021This XXE vulnerability in Dell EMC Avamar Server and IDPA allows remote unauthenticated attackers to cause denial of service or information disclosure...
Jul 16, 2021CVE-2021-21558 is an information disclosure vulnerability in Dell EMC NetWorker backup software where local administrators can read LDAP credentials f...
Jun 8, 2021CVE-2021-21549 is a Cross-Site Request Forgery (CSRF) vulnerability in Dell EMC XtremIO XMS management software. It allows attackers to trick authenti...
May 21, 2021CVE-2021-21505 is a critical vulnerability in Dell EMC Integrated System for Microsoft Azure Stack Hub where an undocumented default iDRAC account exi...
May 6, 2021Why Monitor Dell Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 470+ known vulnerabilities affecting Dell products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Dell packages in under 60 seconds. No agents required - completely agentless scanning that works across Dell deployments.
Free vulnerability database: Access detailed information about every Dell CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Dell CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions