CVE-2016-6649: Command Injection
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface and escalate his privileges to root.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EMC RecoverPointto a version that resolves this vulnerability.Fixed in 4.4.1.1 - Upgrade
Upgrade
EMC RecoverPoint for Virtual Machinesto a version that resolves this vulnerability.Fixed in 5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6649?
CVE-2016-6649 has been assigned a high severity level due to the potential for command injection and privilege escalation.
How do I fix CVE-2016-6649?
To fix CVE-2016-6649, upgrade to EMC RecoverPoint version 4.4.1.1 or later, or EMC RecoverPoint for Virtual Machines version 5.0 or later.
What are the potential impacts of CVE-2016-6649?
The potential impacts of CVE-2016-6649 include unauthorized access to sensitive data and complete control over the affected system due to privilege escalation.
Who is affected by CVE-2016-6649?
CVE-2016-6649 affects users of EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0.
Can CVE-2016-6649 be exploited remotely?
Yes, CVE-2016-6649 can be exploited by a malicious administrator with configuration privileges, allowing for a potential remote attack.