PT-2022-4914 · Dell · Dell Powerprotect Cyber Recovery

CVE-2022-34372

·

Published

2022-08-01

·

Updated

2022-09-07

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell PowerProtect Cyber Recovery versions prior to 19.11.0.2
Description The issue is related to an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API, leading to an authentication bypass. This could allow the attacker to alter docker images, resulting in a loss of integrity and confidentiality.
Recommendations For versions prior to 19.11.0.2, update to version 19.11.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the docker registry API to minimize the risk of exploitation.

Fix

Authentication Bypass Using an Alternate Path or Channel

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06083
CVE-2022-34372

Affected Products

Dell Powerprotect Cyber Recovery