CVE-2026-22273
- EPSS 0.33%
- Veröffentlicht 23.01.2026 09:14:38
- Zuletzt bearbeitet 18.02.2026 13:55:12
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerability in the OS. A low privileged attacker with remote access could potentially exploit this vulnerability, lea...
CVE-2026-22271
- EPSS 0.19%
- Veröffentlicht 23.01.2026 08:54:16
- Zuletzt bearbeitet 18.02.2026 13:55:05
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulner...
CVE-2025-26476
- EPSS 0.12%
- Veröffentlicht 04.08.2025 18:44:50
- Zuletzt bearbeitet 14.01.2026 18:00:08
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
CVE-2025-30483
- EPSS 0.13%
- Veröffentlicht 15.07.2025 14:30:20
- Zuletzt bearbeitet 02.08.2025 01:26:33
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Informati...
CVE-2025-26477
- EPSS 0.39%
- Veröffentlicht 17.04.2025 11:45:19
- Zuletzt bearbeitet 01.08.2025 21:00:56
Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
CVE-2025-26478
- EPSS 0.13%
- Veröffentlicht 17.04.2025 11:37:44
- Zuletzt bearbeitet 01.08.2025 20:55:44
Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
CVE-2024-51540
- EPSS 0.4%
- Veröffentlicht 26.12.2024 16:15:29
- Zuletzt bearbeitet 21.01.2025 21:30:52
Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of ECS. An authenticated user with bucket or object-level access and the necessary privileges could potentially exploit this vulnera...
CVE-2024-52534
- EPSS 0.3%
- Veröffentlicht 25.12.2024 16:15:21
- Zuletzt bearbeitet 21.01.2025 21:30:49
Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
CVE-2024-38485
- EPSS 0.31%
- Veröffentlicht 09.12.2024 15:15:14
- Zuletzt bearbeitet 04.02.2025 16:07:54
Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.
CVE-2024-30473
- EPSS 0.33%
- Veröffentlicht 18.07.2024 16:15:06
- Zuletzt bearbeitet 04.02.2025 17:22:53
Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privileged attacker could potentially exploit this vulnerability, gaining access to unauthorized end points.