Description
Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability leading to gaining access to unauthorized data for a limited time.
Published: 2024-12-13
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-22265 Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability leading to gaining access to unauthorized data for a limited time.
History

Tue, 04 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell recoverpoint For Virtual Machines
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1_p1:*:*:*:*:*:*
Vendors & Products Dell
Dell recoverpoint For Virtual Machines

Fri, 13 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Dec 2024 14:30:00 +0000

Type Values Removed Values Added
Description Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability leading to gaining access to unauthorized data for a limited time.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Dell Recoverpoint For Virtual Machines
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-12-13T20:38:37.546Z

Reserved: 2024-02-01T13:40:59.757Z

Link: CVE-2024-24902

cve-icon Vulnrichment

Updated: 2024-12-13T19:07:12.573Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-13T15:15:26.810

Modified: 2025-02-04T15:54:56.213

Link: CVE-2024-24902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses