Dell System Update 2.3.0.0 之前的版本存在一个“对受限目录路径名限制不当”(路径穿越)漏洞。具有远程访问权限且未经验证身份的 attacker 可能利用该漏洞,从而获得对文件系统的访问权限。由于该漏洞可被未经验证身份的 attacker 用于以 root 权限执行任意代码,因此被认定为严重级别。成功利用该漏洞可能导致受影响的漏洞应用程序及底层操作系统被完全控制。Dell 建议客户尽早升级。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Dell | System Update | < 2.3.0.0 or later |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Dell | System Update | 0 ~ 2.3.0.0 or later | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63688 | 10.0 CRITICAL | Dell CSM <v1.18.0 关键函数缺失认证漏洞 |
| CVE-2026-63692 | 10.0 CRITICAL | Dell Container Storage Modules <1.18.0 缺少身份验证致权限提升 |
| CVE-2026-67269 | 9.9 CRITICAL | Dell CSM Operator <1.18.0 权限提升漏洞 |
| CVE-2026-54472 | 9.8 CRITICAL | Dell Container Storage Modules <1.18.0 硬编码凭据致信息泄露 |
| CVE-2026-61421 | 9.8 CRITICAL | Dell CSM<1.18.0 硬编码凭证致提权 |
| CVE-2026-67273 | 9.6 CRITICAL | Dell Container Storage Modules 提权漏洞 |
| CVE-2026-101207 | 8.8 HIGH | Dell OpenManage <3.7.0 OS命令注入漏洞 |
| CVE-2026-86362 | 8.2 HIGH | Dell System Update <2.3.0.0权限提升漏洞 |
| CVE-2026-86361 | 8.2 HIGH | Dell System Update 2.3.0.0前权限分配错误致提权 |
| CVE-2026-67270 | 8.2 HIGH | Dell CSM<1.18.0证书验证不当致凭据泄露 |
| CVE-2026-61411 | 7.7 HIGH | Dell Container Storage Modules <1.18.0 日志信息泄露 |
| CVE-2026-76105 | 7.7 HIGH | Dell Container Storage Modules 1.18.0前使用随机数不足漏洞 |
| CVE-2026-63697 | 7.6 HIGH | Dell System Update <2.3.0.0 远程执行漏洞 |
| CVE-2026-82162 | 7.4 HIGH | Dell Command Configure 5.2.3.35前版本混合编码提权漏洞 |
| CVE-2026-71168 | 7.3 HIGH | Dell System Update<2.3.0.0路径穿越致远程执行 |
| CVE-2026-70411 | 7.1 HIGH | Dell CSM<1.18.0 gRPC服务缺少身份验证漏洞 |
| CVE-2026-63689 | 6.5 MEDIUM | Dell Container Storage Modules (<1.18.0) 日志敏感信息泄露漏洞 |
| CVE-2026-103778 | 6.2 MEDIUM | Dell Command Configure 5.2.3.35以下版本硬编码密钥漏洞 |
| CVE-2026-63691 | 6.1 MEDIUM | Dell Container Storage Modules <1.18.0 鉴权缺失漏洞 |
| CVE-2026-70414 | 5.5 MEDIUM | Dell Command | Configure 5.2.3.35前明文存储密码漏洞 |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet