CVE-2024-22461

Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any command as root, leading to gaining of root-level access and compromise of complete system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1_p1:*:*:*:*:*:*

History

04 Feb 2025, 15:52

Type Values Removed Values Added
CPE cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1_p1:*:*:*:*:*:*
CWE CWE-78
Summary
  • (es) Dell RecoverPoint for Virtual Machines 6.0.x contiene una vulnerabilidad de inyección de comandos del sistema operativo. Un atacante remoto con pocos privilegios podría aprovechar esta vulnerabilidad ejecutando cualquier comando como superusario, lo que le permitiría obtener acceso a nivel superusario y comprometer todo el sistema.
References () https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities - Vendor Advisory
First Time Dell
Dell recoverpoint For Virtual Machines

13 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-13 14:15

Updated : 2025-02-04 15:52


NVD link : CVE-2024-22461

Mitre link : CVE-2024-22461

CVE.ORG link : CVE-2024-22461


JSON object : View

Products Affected

dell

  • recoverpoint_for_virtual_machines
CWE
CWE-347

Improper Verification of Cryptographic Signature

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')