Improper Authentication Vulnerability in Dell RecoverPoint for Virtual Machines
CVE-2024-38488

9.8CRITICAL

Key Information:

Vendor
Dell
Vendor
CVE Published:
13 December 2024

Summary

Dell RecoverPoint for Virtual Machines 6.0.x contains an improper restriction of excessive authentication vulnerability. This flaw allows a network attacker to potentially exploit the RecoverPoint login form through automated brute force or dictionary attacks on valid user passwords, which could lead to a complete system compromise. It is critical for users to apply necessary updates and security measures to protect against such vulnerabilities.

Affected Version(s)

RecoverPoint for Virtual Machines 6.0 SP1

RecoverPoint for Virtual Machines 6.0 SP1 P1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.