Access Control Flaw in Dell RecoverPoint for Virtual Machines
CVE-2024-24902

6.6MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
13 December 2024

Summary

Dell RecoverPoint for Virtual Machines 6.0.x is impacted by an improper access control vulnerability that allows a low privileged local attacker to potentially gain temporary access to unauthorized data. This vulnerability could lead to a breach of sensitive information within the affected system, highlighting the importance of timely security updates and vigilant access management practices.

Affected Version(s)

RecoverPoint for Virtual Machines 6.0 SP1

RecoverPoint for Virtual Machines 6.0 SP1 P1

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.