Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files that may contain sensitive information
History

Tue, 04 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell recoverpoint For Virtual Machines
Weaknesses CWE-78
CPEs cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1_p1:*:*:*:*:*:*
Vendors & Products Dell
Dell recoverpoint For Virtual Machines

Fri, 13 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Dec 2024 13:45:00 +0000

Type Values Removed Values Added
Description Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files that may contain sensitive information
Weaknesses CWE-11
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-12-13T20:38:56.408Z

Reserved: 2024-10-08T05:40:53.868Z

Link: CVE-2024-48008

cve-icon Vulnrichment

Updated: 2024-12-13T19:07:16.764Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-13T14:15:22.273

Modified: 2025-02-04T15:53:30.747

Link: CVE-2024-48008

cve-icon Redhat

No data.