[UPDATE] [high] Dell ECS: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Dell ECS to escalate privileges, execute arbitrary code with administrator rights, disclose information, manipulate files, conduct a cross-site scripting attack, bypass security measures or cause a denial of service condition.
CSIRTS triage
- What
- Multiple vulnerabilities enable privilege escalation, remote code execution with administrator rights, information disclosure, file manipulation, cross-site scripting, security bypass, and denial of service.
- Who is affected
- All Dell ECS installations.
- Urgency
- High; multiple vectors for privilege escalation and arbitrary code execution with administrator rights.
- Action
- Apply patches addressing all disclosed Dell ECS CVEs: CVE-2018-18074, CVE-2020-10663, CVE-2020-10672, CVE-2020-10673, CVE-2020-10735, CVE-2020-10968, CVE-2020-10969, CVE-2020-11111.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ECS
Get an email when a new ECS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0794
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2018-180747.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 94% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-106636.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 93% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-106723.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 87% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-106738.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 94% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-107355.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 93% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-109683.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 89% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-109693.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 88% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-111113.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 88% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-111123.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 89% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-111136.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 93% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Red Hat FUSE: Multiple vulnerabilitiescert-bund
- mediumCVE-2020-29509: The encoding/xml package in Go (all versions) does not correctly preserve the semantics of att…msrc
- mediumCVE-2020-29511: The encoding/xml package in Go (all versions) does not correctly preserve the semantics of ele…msrc
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25