Dell PowerProtect Data Manager Vulnerability: Unauthorized Access via Weak Password Recovery Mechanism
CVE-2024-22454

8.8HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
13 February 2024

Summary

The vulnerability affects Dell PowerProtect Data Manager versions 19.15 and earlier, which incorporate a weak password recovery mechanism. This flaw enables a remote unauthenticated attacker to exploit the system. The attacker could retrieve a reset password token without proper authorization, allowing them to gain unauthorized access to the application with the privileges of the compromised account. This presents serious security risks, as attackers can manipulate account access and potentially lead to data breaches.

Affected Version(s)

PowerProtect Data Manager 0 <= 19.15

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.