ZeroHour

CVE-2024-22426

CVSS 3.1
9.8 critical
EPSS
1%p71
Published
()
Modified
Description

Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary operating system commands, which will get executed in the context of the root user, resulting in a complete system compromise.

Vendors
dell
Products
recoverpoint for virtual machines
Weakness
CWE-434, CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.