Dell RecoverPoint Virtual Machine Vulnerability Could Lead to Information Disclosure and Unintended Actions

CVE-2024-48008
5.3MEDIUM

Key Information

Vendor
Dell
Status
Recoverpoint For Virtual Machines
Vendor
CVE Published:
13 December 2024

Summary

Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files that may contain sensitive information

Affected Version(s)

RecoverPoint for Virtual Machines = 6.0 SP1

RecoverPoint for Virtual Machines = 6.0 SP1 P1

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

Mitre Database
.