cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2024-25955,https://securityvulnerability.io/vulnerability/CVE-2024-25955,Dell vApp Manager vulnerability: Command injection risk,"Dell vApp Manager, specifically versions prior to 9.2.4.9, is susceptible to a command injection vulnerability. This weakness allows an authorized attacker to execute arbitrary commands by exploiting the flaw within the application. The vulnerability presents significant security risks, enabling malicious actors to manipulate the system beyond intended operations. Dell strongly urges affected users to upgrade to the latest version to mitigate potential exploitation and enhance overall security.",Dell,Virtual Appliance (vapp) Manager,8.8,HIGH,0.0005600000149570405,false,,false,false,false,,,false,false,,2024-03-28T19:05:10.021Z,0 CVE-2024-25946,https://securityvulnerability.io/vulnerability/CVE-2024-25946,Dell vApp Manager vulnerability: Command injection risk,"Dell vApp Manager, before version 9.2.4.9, is susceptible to a command injection vulnerability that may allow an authorized attacker to execute arbitrary commands on the system. This security flaw underscores the critical need for users to upgrade their software to the latest version to mitigate potential risks. By addressing this vulnerability, organizations improve their security posture and protect their systems against attacks that could exploit such weaknesses.",Dell,Virtual Appliance (vapp) Manager,8.8,HIGH,0.0005600000149570405,false,,false,false,false,,,false,false,,2024-03-28T19:00:18.175Z,0 CVE-2023-48671,https://securityvulnerability.io/vulnerability/CVE-2023-48671,Information Disclosure Vulnerability in Dell vApp Manager,"Dell vApp Manager versions prior to 9.2.4.x are susceptible to an information disclosure vulnerability. This security issue may allow a remote attacker to access sensitive information, which could facilitate further attacks on the affected systems. It is crucial for users of impacted versions to apply the latest updates to mitigate potential threats effectively.",Dell,vApp Manager,7.5,HIGH,0.0020600000862032175,false,,false,false,false,,,false,false,,2023-12-14T17:15:00.000Z,0 CVE-2023-48663,https://securityvulnerability.io/vulnerability/CVE-2023-48663,Command Injection Vulnerability in Dell vApp Manager,"Dell vApp Manager prior to version 9.2.4.x is susceptible to a command injection vulnerability that allows a remote attacker with elevated privileges to potentially execute arbitrary OS commands on the affected system. This issue raises significant security concerns, as it could be exploited to gain unauthorized access and control over system functions, undermining the integrity and confidentiality of the system.",Dell,vApp Manager,7.2,HIGH,0.001180000021122396,false,,false,false,false,,,false,false,,2023-12-14T16:15:00.000Z,0 CVE-2023-48665,https://securityvulnerability.io/vulnerability/CVE-2023-48665,Command Injection Vulnerability in Dell vApp Manager Affects System Security,"Dell vApp Manager versions prior to 9.2.4.x are susceptible to a command injection vulnerability. A remote attacker with elevated privileges could exploit this flaw, enabling them to execute arbitrary operating system commands on the compromised system. This situation poses a significant risk to the integrity and confidentiality of the affected installations, necessitating prompt attention and remediation.",Dell,"vApp Manager,",7.2,HIGH,0.001180000021122396,false,,false,false,false,,,false,false,,2023-12-14T16:15:00.000Z,0 CVE-2023-48662,https://securityvulnerability.io/vulnerability/CVE-2023-48662,Command Injection Vulnerability in Dell vApp Manager,"Dell vApp Manager, prior to version 9.2.4.x, is susceptible to a command injection vulnerability that allows a remote attacker with elevated privileges to execute arbitrary operating system commands. This exploitation potential poses a significant security risk to the affected systems, as it can lead to unauthorized access and control. Organizations using impacted versions are advised to update to the latest version to mitigate this vulnerability and secure their systems.",Dell,vApp Manager,7.2,HIGH,0.001180000021122396,false,,false,false,false,,,false,false,,2023-12-14T16:15:00.000Z,0 CVE-2023-48664,https://securityvulnerability.io/vulnerability/CVE-2023-48664,Command Injection Vulnerability in Dell vApp Manager Software,"Dell vApp Manager prior to version 9.2.4.x is affected by a command injection vulnerability that allows remote users with elevated privileges to execute arbitrary operating system commands. Exploiting this vulnerability could compromise the integrity of the affected system, leading to potential unauthorized access and control.",Dell,vApp Manager,7.2,HIGH,0.001180000021122396,false,,false,false,false,,,false,false,,2023-12-14T16:15:00.000Z,0 CVE-2023-48661,https://securityvulnerability.io/vulnerability/CVE-2023-48661,Arbitrary File Read Vulnerability in Dell vApp Manager,"Dell vApp Manager, in versions prior to 9.2.4.x, has a security weakness that allows a remote user with elevated privileges to read arbitrary files from the system. This issue can be exploited, leading to exposure of sensitive information stored on the server, posing significant risks to the system's integrity. It is crucial for users of affected versions to implement corrective measures as recommended by the vendor.",Dell,vApp Manager,4.9,MEDIUM,0.0006399999838322401,false,,false,false,false,,,false,false,,2023-12-14T16:15:00.000Z,0 CVE-2018-1215,https://securityvulnerability.io/vulnerability/CVE-2018-1215,,"An arbitrary file upload vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.21, Dell EMC VASA Virtual Appliance versions prior to 8.4.0.514, and Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier). A remote authenticated malicious user may potentially upload arbitrary maliciously crafted files in any location on the web server. By chaining this vulnerability with CVE-2018-1216, the attacker may use the default account to exploit this vulnerability.",Dell,"Vapp Manager Which Is Embedded In Dell Emc Unisphere For Vmax, Dell Emc Solutions Enabler, Dell Emc Vasa Virtual Appliances, And Dell Emc Vmax Embedded Management (emanagement)",8.8,HIGH,0.0041600000113248825,false,,false,false,false,,,false,false,,2018-03-08T15:00:00.000Z,0 CVE-2018-1216,https://securityvulnerability.io/vulnerability/CVE-2018-1216,,"A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.21, Dell EMC VASA Virtual Appliance versions prior to 8.4.0.514, and Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier). They contain an undocumented default account (smc) with a hard-coded password that may be used with certain web servlets. A remote attacker with the knowledge of the hard-coded password and the message format may use vulnerable servlets to gain unauthorized access to the system. Note: This account cannot be used to log in via the web user interface.",Dell,"Vapp Manager Which Is Embedded In Dell Emc Unisphere For Vmax, Dell Emc Solutions Enabler, Dell Emc Vasa Virtual Appliances, And Dell Emc Vmax Embedded Management (emanagement)",9.8,CRITICAL,0.011760000139474869,false,,false,false,false,,,false,false,,2018-03-08T15:00:00.000Z,0