Access Control Flaw in Dell RecoverPoint for Virtual Machines
CVE-2024-24902
6.6MEDIUM
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 13 December 2024
Summary
Dell RecoverPoint for Virtual Machines 6.0.x is impacted by an improper access control vulnerability that allows a low privileged local attacker to potentially gain temporary access to unauthorized data. This vulnerability could lead to a breach of sensitive information within the affected system, highlighting the importance of timely security updates and vigilant access management practices.
Affected Version(s)
RecoverPoint for Virtual Machines 6.0 SP1
RecoverPoint for Virtual Machines 6.0 SP1 P1
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved