Description
Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality
Published: 2022-09-01
Score: 9.8 Critical
EPSS: 1.9% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-37327 Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality
History

No history.

Subscriptions

Dell Powerprotect Cyber Recovery
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-17T01:41:50.914Z

Reserved: 2022-06-23T00:00:00.000Z

Link: CVE-2022-34372

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-09-01T19:15:12.357

Modified: 2024-11-21T07:09:22.440

Link: CVE-2022-34372

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses