Command Injection Vulnerability in EMC RecoverPoint for Virtual Machines
CVE-2018-1185

6.7MEDIUM

Summary

A command injection vulnerability exists in the Admin CLI of EMC RecoverPoint for Virtual Machines, which allows a user with administrator privileges to escape the restricted shell. This breach can enable the execution of arbitrary commands with root privileges, posing a significant risk to system integrity and security. It is crucial for administrators using affected versions to implement immediate updates and reviews of system access to prevent exploitation.

Affected Version(s)

EMC RecoverPoint for Virtual Machines prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, EMC RecoverPoint prior to 5.0.1.3 EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, EMC RecoverPoint versions prior to 5.0.1.3

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.