First published: Tue May 29 2018(Updated: )
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to execute arbitrary commands on the affected system with root privilege.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RecoverPoint | <5.1.2 | |
EMC RecoverPoint for Virtual Machines | <5.1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1235 is a command injection vulnerability found in Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3.
CVE-2018-1235 has a severity rating of 9.8, which is considered critical.
An unauthenticated remote attacker can exploit CVE-2018-1235 to execute arbitrary commands on the affected system with root privilege.
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3 are affected by CVE-2018-1235.
To fix CVE-2018-1235, upgrade Dell EMC RecoverPoint to version 5.1.2 or higher and RecoverPoint for VMs to version 5.1.1.3 or higher.