PT-2022-4914 · Dell · Dell Powerprotect Cyber Recovery
Published
2022-08-01
·
Updated
2022-09-07
·
CVE-2022-34372
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dell PowerProtect Cyber Recovery versions prior to 19.11.0.2
Description
The issue is related to an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the
docker registry API, leading to an authentication bypass. This could allow the attacker to alter docker images, resulting in a loss of integrity and confidentiality.Recommendations
For versions prior to 19.11.0.2, update to version 19.11.0.2 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
docker registry API to minimize the risk of exploitation.Fix
Authentication Bypass Using an Alternate Path or Channel
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Powerprotect Cyber Recovery