<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Unity</title>
  <link>https://cvedaily.com/pages/tags/unity.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/unity.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Unity</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:52 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-20035 – A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20035</guid>
    <pubDate>Wed, 06 May 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20035</strong></p>
  <p>A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device.  This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20034 – A vulnerability in the web-based management interface of Cisco Unity Connection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20034</guid>
    <pubDate>Wed, 06 May 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20034</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to execute arbit…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20081 – Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20081</guid>
    <pubDate>Wed, 15 Apr 2026 17:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20081</strong></p>
  <p>Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker&nbsp;to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials.&nbsp;  These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vuln…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20078 – Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20078</guid>
    <pubDate>Wed, 15 Apr 2026 17:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20078</strong></p>
  <p>Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker&nbsp;to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials.&nbsp;  These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vuln…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20061 – A vulnerability in the web-based management interface of Cisco Unity Connection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20061</guid>
    <pubDate>Wed, 15 Apr 2026 17:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20061</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit thi…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20060 – A vulnerability in the web-based management interface of Cisco Unity Connection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20060</guid>
    <pubDate>Wed, 15 Apr 2026 17:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20060</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.  This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to r…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20059 – A vulnerability in the web-based management interface of Cisco Unity Connection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20059</guid>
    <pubDate>Wed, 15 Apr 2026 17:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20059</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface.  This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27478 – Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27478</guid>
    <pubDate>Wed, 11 Mar 2026 20:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27478</strong></p>
  <p>Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (/api/1.0/unity-control/auth/tokens). The endpoint extracts the issuer (iss) claim from incoming JWTs and uses it to dynamically fetch the JWKS endpoint for signature validation without validating that the issuer is…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25918 – unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25918</guid>
    <pubDate>Mon, 09 Feb 2026 22:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25918</strong></p>
  <p>unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments including --email and --password are output via JSON.stringify without sanitization, exposing secrets to shell history, CI/CD logs, and log aggregation systems.…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21418 – Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21418</guid>
    <pubDate>Fri, 30 Jan 2026 09:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21418</strong></p>
  <p>Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20045 – A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20045</guid>
    <pubDate>Wed, 21 Jan 2026 17:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20045</strong></p>
  <p>A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlyin…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46423 – Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46423</guid>
    <pubDate>Thu, 30 Oct 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46423</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46422 – Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46422</guid>
    <pubDate>Thu, 30 Oct 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46422</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43942 – Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43942</guid>
    <pubDate>Thu, 30 Oct 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43942</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43941 – Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43941</guid>
    <pubDate>Thu, 30 Oct 2025 14:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43941</strong></p>
  <p>Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary command with root privileges. This vulnerability only affects systems without a valid license install.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43940 – Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43940</guid>
    <pubDate>Thu, 30 Oct 2025 14:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43940</strong></p>
  <p>Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43939 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43939</guid>
    <pubDate>Thu, 30 Oct 2025 14:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43939</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59489 – Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows arg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59489</guid>
    <pubDate>Fri, 03 Oct 2025 14:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59489</strong></p>
  <p>Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that applic…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52800 – Missing Authorization vulnerability in Unity Business Technology Pty Ltd The E-C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52800</guid>
    <pubDate>Thu, 14 Aug 2025 11:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52800</strong></p>
  <p>Missing Authorization vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects The E-Commerce ERP: from n/a through <= 2.1.1.3.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36607 – Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36607</guid>
    <pubDate>Mon, 04 Aug 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36607</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36606 – Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36606</guid>
    <pubDate>Mon, 04 Aug 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36606</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36605 – Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36605</guid>
    <pubDate>Mon, 04 Aug 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36605</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScri…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36604 – Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36604</guid>
    <pubDate>Mon, 04 Aug 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36604</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8399 – The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8399</guid>
    <pubDate>Sat, 02 Aug 2025 09:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8399</strong></p>
  <p>The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-52836 – Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Lt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52836</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52836</guid>
    <pubDate>Wed, 16 Jul 2025 12:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-52836</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Privilege Escalation.This issue affects The E-Commerce ERP: from n/a through <= 2.1.1.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52836">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24386 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24386</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24386</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24385 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24385</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24385</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24381 – Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24381</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24381</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge se…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24380 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24380</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24380</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24379 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24379</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24379</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24378 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24378</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24378</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24377 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24377</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24377</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23383 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23383</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23383</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49601 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49601</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49601</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-24383 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24383</guid>
    <pubDate>Fri, 28 Mar 2025 02:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-24383</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is considered critical as it can be leveraged to delete critical system files as root. Dell recommends…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24382 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24382</guid>
    <pubDate>Fri, 28 Mar 2025 02:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24382</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-22398 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22398</guid>
    <pubDate>Fri, 28 Mar 2025 02:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-22398</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root. Exploitation may lead to a system take over by an attacker. This vulnerability is considered critica…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49565 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49565</guid>
    <pubDate>Fri, 28 Mar 2025 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49565</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49564 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49564</guid>
    <pubDate>Fri, 28 Mar 2025 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49564</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges and elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49563 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49563</guid>
    <pubDate>Fri, 28 Mar 2025 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49563</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges and elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3532 – A vulnerability in the web-based management interface of Cisco&amp;nbsp;Unified Comm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3532</guid>
    <pubDate>Mon, 18 Nov 2024 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3532</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco&nbsp;Unified Communications Manager, Cisco&nbsp;Unified Communications Manager Session Management Edition, Cisco&nbsp;Unified Communications Manager IM &amp; Presence Service, and Cisco&nbsp;Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31145 – Certain PCI devices in a system might be assigned Reserved Memory
Regions (speci...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31145</guid>
    <pubDate>Wed, 25 Sep 2024 11:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31145</strong></p>
  <p>Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi.  These are typically used for platform tasks such as legacy USB emulation.  Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions n…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-4999 – A vulnerability in the web-based management interface of multiple Ligowave devic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4999</guid>
    <pubDate>Thu, 16 May 2024 13:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-4999</strong></p>
  <p>A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22230 – Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22230</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22230</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could potentially exploit this vulnerability, stealing session information, masquerading as the affected user or carry out any actions that this user could perform, or to generally control the victim's browser.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22228 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22228</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22228</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22227 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22227</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22227</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability execute commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-22226 – Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22226</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-22226</strong></p>
  <p>Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, to gain unauthorized write access to the files stored on the server filesystem, with elevated privileges.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22225 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22225</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22225</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22224 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22224</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22224</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22223 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22223</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22223</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22222 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22222</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22222</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22221 – Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22221</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22221</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially exploit this vulnerability, leading to exposure of sensitive information.</p>
  <p><strong>CVSS:</strong> 4.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0170 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0170</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0170</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0169 – Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0169</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0169</strong></p>
  <p>Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0168 – Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0168</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0168</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to inject arbitrary operating system commands. This vulnerability allows an authenticated attacker to execute commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0167 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0167</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0167</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0167</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0167">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0166 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0166</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0166</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0165 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0165</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0165</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0164 – Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0164</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0164</strong></p>
  <p>Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary commands with elevated privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-1113 – A vulnerability, which was classified as critical, was found in openBI up to 1.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1113</guid>
    <pubDate>Wed, 31 Jan 2024 20:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-1113</strong></p>
  <p>A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadUnity of the file /application/index/controller/Unity.php. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerabilit…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20305 – A vulnerability in the web-based management interface of Cisco Unity Connection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20305</guid>
    <pubDate>Fri, 26 Jan 2024 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20305</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the int…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-22229 – Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22229</guid>
    <pubDate>Wed, 24 Jan 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-22229</strong></p>
  <p>Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20272 – A vulnerability in the web-based management interface of Cisco Unity Connection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20272</guid>
    <pubDate>Wed, 17 Jan 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20272</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system and execute commands on the underlying operating system. This vulnerability is due to a lack of authentication in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43082 – Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43082</guid>
    <pubDate>Wed, 22 Nov 2023 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43082</strong></p>
  <p>Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-4804 – An unauthorized user could access debug features in Quantum HD Unity products th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4804</guid>
    <pubDate>Fri, 10 Nov 2023 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-4804</strong></p>
  <p>An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-489</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-43067 – Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43067</guid>
    <pubDate>Mon, 23 Oct 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-43067</strong></p>
  <p>Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploit this vulnerability disclosing local files in the file system.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-43066 – Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43066</guid>
    <pubDate>Mon, 23 Oct 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-43066</strong></p>
  <p>Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local attacker to exploit this vulnerability by authenticating to the device CLI and issuing certain commands.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-43074 – Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43074</guid>
    <pubDate>Mon, 23 Oct 2023 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-43074</strong></p>
  <p>Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server.</p>
  <p><strong>CVSS:</strong> 5.2 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-43065 – Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability. A low-pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43065</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43065</guid>
    <pubDate>Mon, 23 Oct 2023 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-43065</strong></p>
  <p>Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability. A low-privileged authenticated attacker can exploit these issues to obtain escalated privileges.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43065">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-20266 – A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20266</guid>
    <pubDate>Wed, 30 Aug 2023 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-20266</strong></p>
  <p>A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an authenticated, remote attacker to elevate privileges to root on an affected device.  This vulnerability exists because the application does not properly restrict the files that…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37250 – Unity Parsec has a TOCTOU race condition that permits local attackers to escalat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37250</guid>
    <pubDate>Sun, 20 Aug 2023 08:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37250</strong></p>
  <p>Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22564 – Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22564</guid>
    <pubDate>Tue, 14 Feb 2023 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22564</strong></p>
  <p>Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm. A remote unauthenticated attacker could potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45788 – A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45788</guid>
    <pubDate>Mon, 30 Jan 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45788</strong></p>
  <p>A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Ve…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-37300 – A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37300</guid>
    <pubDate>Mon, 12 Sep 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-37300</strong></p>
  <p>A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions (former name of EcoStruxure Control Expert) (V15.0 SP1 and prior), EcoStruxure Process Expert, Including all versions of E…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-20859 – A vulnerability in the Disaster Recovery framework of Cisco Unified Communicatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20859</guid>
    <pubDate>Wed, 06 Jul 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-20859</strong></p>
  <p>A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to. This vulnerability is due to insufficient access control checks o…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-20800 – A vulnerability in the web-based management interface of Cisco Unified Communica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20800</guid>
    <pubDate>Wed, 06 Jul 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-20800</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack a…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-20752 – A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20752</guid>
    <pubDate>Wed, 06 Jul 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-20752</strong></p>
  <p>A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is due to insufficient protection of a system password. An attacker could exploit this vulnerability by observing the time it…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-208</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-29085 – Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29085</guid>
    <pubDate>Thu, 02 Jun 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-29085</strong></p>
  <p>Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored in plain text. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29084 – Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29084</guid>
    <pubDate>Thu, 02 Jun 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29084</strong></p>
  <p>Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-29091 – Dell Unity, Dell UnityVSA, and Dell UnityXT versions prior to 5.2.0.0.5.173 cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29091</guid>
    <pubDate>Thu, 26 May 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-29091</strong></p>
  <p>Dell Unity, Dell UnityVSA, and Dell UnityXT versions prior to 5.2.0.0.5.173 contain a Reflected Cross-Site Scripting Vulnerability in Unisphere GUI. An Unauthenticated Remote Attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to i…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-20788 – A vulnerability in the web-based management interface of Cisco Unified Communica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20788</guid>
    <pubDate>Thu, 21 Apr 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-20788</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22797 – A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Tra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22797</guid>
    <pubDate>Wed, 13 Apr 2022 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22797</strong></p>
  <p>A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including for…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26361 – IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26361</guid>
    <pubDate>Tue, 05 Apr 2022 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26361</strong></p>
  <p>IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for p…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26360 – IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26360</guid>
    <pubDate>Tue, 05 Apr 2022 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26360</strong></p>
  <p>IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for p…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26359 – IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26359</guid>
    <pubDate>Tue, 05 Apr 2022 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26359</strong></p>
  <p>IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for p…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26358 – IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26358</guid>
    <pubDate>Tue, 05 Apr 2022 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26358</strong></p>
  <p>IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for p…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-43589 – Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43589</guid>
    <pubDate>Mon, 24 Jan 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-43589</strong></p>
  <p>Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated user with high privileges may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the Unity underlying OS, with the privileges of the vulnerable application. Exploitation may lead…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-34701 – A vulnerability in the web-based management interface of Cisco Unified Communica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34701</guid>
    <pubDate>Thu, 04 Nov 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-34701</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), and Cisco Unity Connection could allow an authenticated, remote attacker to access sensitive data on an affected device. Th…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22792 – A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22792</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22792</guid>
    <pubDate>Thu, 02 Sep 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22792</strong></p>
  <p>A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Mome…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22792">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22791 – A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Servic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22791</guid>
    <pubDate>Thu, 02 Sep 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22791</strong></p>
  <p>A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22790 – A CWE-125: Out-of-bounds Read vulnerability that could cause a Denial of Service...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22790</guid>
    <pubDate>Thu, 02 Sep 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22790</strong></p>
  <p>A CWE-125: Out-of-bounds Read vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum E…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22789 – A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22789</guid>
    <pubDate>Thu, 02 Sep 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22789</strong></p>
  <p>A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (pa…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22782 – Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22782</guid>
    <pubDate>Wed, 14 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22782</strong></p>
  <p>Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause an information leak allowing disclosure of network and process information, cr…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22781 – Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22781</guid>
    <pubDate>Wed, 14 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22781</strong></p>
  <p>Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause a leak of SMTP credential used for mailbox authentication when an attacker can…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22780 – Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22780</guid>
    <pubDate>Wed, 14 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22780</strong></p>
  <p>Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause unauthorized access to a project file protected by a password when this file i…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-22779 – Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22779</guid>
    <pubDate>Wed, 14 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-22779</strong></p>
  <p>Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*),…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22778 – Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22778</guid>
    <pubDate>Wed, 14 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22778</strong></p>
  <p>Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause protected derived function blocks to be read or modified by unauthorized users…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21591 – Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21591</guid>
    <pubDate>Mon, 12 Jul 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21591</strong></p>
  <p>Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21590 – Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21590</guid>
    <pubDate>Mon, 12 Jul 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21590</strong></p>
  <p>Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21589 – Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21589</guid>
    <pubDate>Mon, 12 Jul 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21589</strong></p>
  <p>Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not exit on failed Initialization. A local authenticated Service user could potentially exploit this vulnerability to escalate privileges.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21589">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
