First published: Fri Dec 13 2024(Updated: )
Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any command as root, leading to gaining of root-level access and compromise of complete system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RecoverPoint | >5.0<=6.0.x | |
EMC RecoverPoint | =6.0-sp1 | |
EMC RecoverPoint | =6.0-sp1_p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22461 is considered a high-severity OS Command injection vulnerability.
To fix CVE-2024-22461, upgrade to the patched version of Dell RecoverPoint for Virtual Machines provided by Dell.
CVE-2024-22461 affects versions 5.0 to 6.0.x of Dell RecoverPoint for Virtual Machines.
Yes, CVE-2024-22461 allows a low privileged remote attacker to execute commands as root, leading to potential system compromise.
If exploited, CVE-2024-22461 could result in complete system compromise due to unauthorized root access.