First published: Fri Feb 03 2017(Updated: )
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface and escalate his privileges to root.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RecoverPoint Appliance | <=4.4.1.0 | |
EMC RecoverPoint | <=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6649 has been assigned a high severity level due to the potential for command injection and privilege escalation.
To fix CVE-2016-6649, upgrade to EMC RecoverPoint version 4.4.1.1 or later, or EMC RecoverPoint for Virtual Machines version 5.0 or later.
The potential impacts of CVE-2016-6649 include unauthorized access to sensitive data and complete control over the affected system due to privilege escalation.
CVE-2016-6649 affects users of EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0.
Yes, CVE-2016-6649 can be exploited by a malicious administrator with configuration privileges, allowing for a potential remote attack.