CVE-2024-22425
16.02.2024, 12:15
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to launch a brute force attack or a dictionary attack against the RecoverPoint login form. This allows attackers to brute-force the password of valid users in an automated manner.Enginsight
Vendor | Product | Version |
---|---|---|
dell | recoverpoint_for_virtual_machines | 5.3:sp2 |
dell | recoverpoint_for_virtual_machines | 5.3:sp2_p1 |
dell | recoverpoint_for_virtual_machines | 5.3:sp2_p2 |
dell | recoverpoint_for_virtual_machines | 5.3:sp2_p4 |
dell | recoverpoint_for_virtual_machines | 5.3:sp3_p1 |
dell | recoverpoint_for_virtual_machines | 5.3:sp3_p2 |
dell | recoverpoint_for_virtual_machines | 6.0:sp1 |
𝑥
= Vulnerable software versions
References