PT-2024-19414 · Dell · Dell Recoverpoint For Virtual Machines

Published

2024-02-16

·

Updated

2024-08-29

·

CVE-2024-22425

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell RecoverPoint for Virtual Machines versions 5.3.x through 6.0.SP1
Description The issue allows an unauthenticated remote attacker to launch a brute force attack or a dictionary attack against the RecoverPoint login form, enabling them to brute-force the password of valid users in an automated manner.
Recommendations For versions 5.3.x through 6.0.SP1, consider temporarily restricting access to the login form to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2024-22425

Affected Products

Dell Recoverpoint For Virtual Machines