Dell PowerProtect Data Manager Vulnerability: Unauthorized Access via Weak Password Recovery Mechanism
CVE-2024-22454
8.8HIGH
Summary
The vulnerability affects Dell PowerProtect Data Manager versions 19.15 and earlier, which incorporate a weak password recovery mechanism. This flaw enables a remote unauthenticated attacker to exploit the system. The attacker could retrieve a reset password token without proper authorization, allowing them to gain unauthorized access to the application with the privileges of the compromised account. This presents serious security risks, as attackers can manipulate account access and potentially lead to data breaches.
Affected Version(s)
PowerProtect Data Manager 0 <= 19.15
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved