First published: Tue Nov 13 2018(Updated: )
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an information disclosure vulnerability. A malicious boxmgmt user may potentially be able to determine the existence of any system file via Boxmgmt CLI.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RecoverPoint | <5.1.2.1 | |
EMC RecoverPoint for Virtual Machines | <5.2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15771 is an information disclosure vulnerability in Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2.
The severity of CVE-2018-15771 is medium with a severity value of 5.5.
CVE-2018-15771 allows a malicious user to determine the existence of any system file via Boxmgmt CLI in Dell EMC RecoverPoint versions prior to 5.1.2.1.
CVE-2018-15771 allows a malicious user to determine the existence of any system file via Boxmgmt CLI in Dell EMC RecoverPoint for VMs versions prior to 5.2.0.2.
To mitigate CVE-2018-15771, update your Dell EMC RecoverPoint to version 5.1.2.1 or later, and update your Dell EMC RecoverPoint for VMs to version 5.2.0.2 or later.