CVE-2025-36572
- EPSS 0.07%
- Published 28.05.2025 16:14:20
- Last modified 09.06.2025 18:58:23
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit thi...
CVE-2024-51532
- EPSS 0.17%
- Published 19.12.2024 02:15:23
- Last modified 29.01.2025 21:06:51
Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitra...
CVE-2023-32478
- EPSS 0.16%
- Published 21.07.2023 06:15:09
- Last modified 21.11.2024 08:03:26
Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exploit this vulnerability, leading to sensitive information disclosure.
CVE-2022-26870
- EPSS 0.29%
- Published 21.10.2022 18:15:09
- Last modified 21.11.2024 06:54:43
Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon successful e...
CVE-2022-22556
- EPSS 1.06%
- Published 02.06.2022 21:15:07
- Last modified 21.11.2024 06:47:01
Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the Denial of Service.
CVE-2022-22557
- EPSS 0.11%
- Published 02.06.2022 21:15:07
- Last modified 21.11.2024 06:47:01
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain us...
CVE-2022-26866
- EPSS 0.32%
- Published 02.06.2022 21:15:07
- Last modified 21.11.2024 06:54:42
Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged network attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted...
- EPSS 0.37%
- Published 02.06.2022 21:15:07
- Last modified 21.11.2024 06:54:42
PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as for...
CVE-2022-26868
- EPSS 0.11%
- Published 02.06.2022 21:15:07
- Last modified 21.11.2024 06:54:42
Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's unde...
CVE-2022-26869
- EPSS 3.19%
- Published 02.06.2022 21:15:07
- Last modified 21.11.2024 06:54:42
Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and arbitrary code execution.