PT-2017-9007 · Emc · Emc Recoverpoint+1

Published

2017-02-03

·

Updated

2017-03-08

·

CVE-2016-6649

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EMC RecoverPoint versions prior to 4.4.1.1 EMC RecoverPoint for Virtual Machines versions prior to 5.0
Description The issue allows a malicious administrator with configuration privileges to bypass the user interface and escalate privileges to root through multiple command injection vulnerabilities.
Recommendations For EMC RecoverPoint versions prior to 4.4.1.1, update to version 4.4.1.1 or later. For EMC RecoverPoint for Virtual Machines versions prior to 5.0, update to version 5.0 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6649

Affected Products

Emc Recoverpoint
Dell Recoverpoint For Virtual Machines