CVE-2018-15771: Dell EMC RecoverPoint Information Disclosure Vulnerability
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an information disclosure vulnerability. A malicious boxmgmt user may potentially be able to determine the existence of any system file via Boxmgmt CLI.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15771?
CVE-2018-15771 is an information disclosure vulnerability in Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2.
What is the severity of CVE-2018-15771?
The severity of CVE-2018-15771 is medium with a severity value of 5.5.
How does CVE-2018-15771 affect Dell EMC RecoverPoint?
CVE-2018-15771 allows a malicious user to determine the existence of any system file via Boxmgmt CLI in Dell EMC RecoverPoint versions prior to 5.1.2.1.
How does CVE-2018-15771 affect Dell EMC RecoverPoint for VMs?
CVE-2018-15771 allows a malicious user to determine the existence of any system file via Boxmgmt CLI in Dell EMC RecoverPoint for VMs versions prior to 5.2.0.2.
How can I mitigate CVE-2018-15771?
To mitigate CVE-2018-15771, update your Dell EMC RecoverPoint to version 5.1.2.1 or later, and update your Dell EMC RecoverPoint for VMs to version 5.2.0.2 or later.