First published: Thu Jul 07 2022(Updated: )
Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appliance deployments. A lower-privileged authenticated user can chain docker commands to escalate privileges to root leading to complete system takeover.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell PowerProtect | <19.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32481 is classified as a high severity vulnerability due to its potential for complete system takeover.
The recommended fix for CVE-2022-32481 is to upgrade Dell PowerProtect Cyber Recovery to version 19.11 or later.
CVE-2022-32481 affects users of Dell PowerProtect Cyber Recovery with versions prior to 19.11 on virtual appliance deployments.
CVE-2022-32481 is a privilege escalation vulnerability.
CVE-2022-32481 can be exploited by a lower-privileged authenticated user within the system.