Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files that may contain sensitive information
References
Configurations
Configuration 1 (hide)
|
History
04 Feb 2025, 15:53
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1_p1:*:*:*:*:*:* cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1:*:*:*:*:*:* |
|
CWE | CWE-78 | |
First Time |
Dell
Dell recoverpoint For Virtual Machines |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
References | () https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities - Vendor Advisory |
13 Dec 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-13 14:15
Updated : 2025-02-04 15:53
NVD link : CVE-2024-48008
Mitre link : CVE-2024-48008
JSON object : View
Products Affected
dell
- recoverpoint_for_virtual_machines
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')