Known vulnerabilities in Dell Storage Manager

Vendor: Dell
Software CPE: cpe:2.3:a:dell:dell_storage_manager:*:*:*:*:*:*:*:*
Total vulnerabilities: 18
Public exploits: 7
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Dell Storage Manager Dell Storage Manager is affected by 18 known vulnerabilities: 1 critical, 4 high, 7 medium, 6 low Critical High Medium Low

Vulnerabilities (18)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU117670 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2025-46425
CWE-611 Medium
No
No
2020 R1.22 27.10.2025 SB2025102722
#VU117669 - Missing Authentication for Critical Function
CVE-2025-43994
CWE-306 Medium
Available
No
2020 R1.22 27.10.2025 SB2025102722
#VU117668 - Improper Authentication
CVE-2025-43995
CWE-287 High
Available
No
2020 R1.22 27.10.2025 SB2025102722
#VU109613 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-23379
CWE-79 Low
No
No
2020 R1.21 21.05.2025 SB20250521140
#VU109612 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-22476
CWE-78 Medium
No
No
2020 R1.21 21.05.2025 SB20250521140
#VU109611 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2025-22478
CWE-611 High
No
No
2020 R1.21 21.05.2025 SB20250521140
#VU109610 - Improper Authentication
CVE-2025-22477
CWE-287 High
No
No
2020 R1.21 21.05.2025 SB20250521140
#VU109609 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-22479
CWE-22 Medium
No
No
2020 R1.21 21.05.2025 SB20250521140
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Available
No
2020 R1.21 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 343 more
#VU73970 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-48285
CWE-22 Medium
No
No
2020 R1.21 23.03.2023 SB2023032314
SB2023032315
SB2023042510
and 22 more
#VU59051 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-45105
CWE-835 Medium
Available
No
20.1.2 18.12.2021 SB2021121802
SB2021121903
SB2021122011
and 169 more
#VU58976 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-45046
CWE-94 High
Available
Exploited
20.1.2 15.12.2021 SB2021121504
SB2021121511
SB2021121512
and 178 more
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Available
Exploited
20.1.2 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU55579 - Resource exhaustion
CVE-2021-23413
CWE-400 Medium
No
No
2020 R1.21 04.08.2021 SB2021080408
SB2022081837
SB20230418118
and 4 more
#VU29032 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-7676
CWE-79 Low
No
No
2020 R1.21 16.06.2020 SB2020061604
SB2021072628
SB2021072629
and 19 more
#VU27519 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11023
CWE-79 Low
Available
Exploited
2020 R1.21 05.05.2020 SB2020042126
SB2020052033
SB2020052103
and 180 more
#VU27052 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11022
CWE-79 Low
Available
No
2020 R1.21 21.04.2020 SB2020042126
SB2020052033
SB2020052103
and 181 more
#VU14150 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-9251
CWE-79 Low
No
No
2020 R1.21 31.07.2018 SB2018080106
SB2019011705
SB2019100301
and 63 more