Emc Unityvsa Operating Environment
Vendor:
First CVE: May 8, 2018 · Active for 8 years
15
Total CVEs
More Total CVEs than 91% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Emc Unityvsa Operating Environment over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 8, 2018
8 years ago
Most Recent CVE
Feb 14, 2023
1,260 days ago
CVE Severity & Scoring
Emc Unityvsa Operating Environment15 CVEs
73%
27%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local8 (53.3%)
Network7 (46.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (93.3%)
High1 (6.7%)
Unknown0 (0.0%)
User Interaction
None13 (86.7%)
Unknown0 (0.0%)
Required2 (13.3%)
Privileges Required
Low4 (26.7%)
High7 (46.7%)
None4 (26.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1239HIGH Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injection vulnerabilities. A remote application admin user could po | May 8, 2018 | 7.2 | 25 | NO | NO |
CVE-2019-3741HIGH Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere user’s (including the admin privilege user) password is | Jul 18, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-11064HIGH Dell EMC Unity OE versions 4.3.0.x and 4.3.1.x and UnityVSA OE versions 4.3.0.x and 4.3.1.x contains an Incorrect File Permissions vulnerability. A locally authenticated malicious | Oct 5, 2018 | 7.8 | 24 | NO | NO |
CVE-2019-3754MEDIUM Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe3200 versions prior to 3.1.10.9946299 conta | Sep 3, 2019 | 6.1 | 23 | NO | NO |
CVE-2021-43589MEDIUM Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated us | Jan 24, 2022 | 6.7 | 22 | NO | NO |
CVE-2021-21591MEDIUM Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the | Jul 12, 2021 | 6.7 | 22 | NO | NO |
CVE-2021-21590MEDIUM Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the | Jul 12, 2021 | 6.7 | 22 | NO | NO |
CVE-2022-22564MEDIUM Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm. A remote unauthenticated attacker could potentially exploit this vulnerability by performing | Feb 14, 2023 | 5.9 | 21 | NO | NO |
CVE-2021-21589MEDIUM Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not exit on failed Initialization. A local authenticated Service user could potentially exploit this vulne | Jul 12, 2021 | 6.7 | 21 | NO | NO |
CVE-2020-29490MEDIUM Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker co | Jan 5, 2021 | 6.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Emc Unityvsa Operating Environment
Top CWEs
Versions
No cataloged versions.