CVE-2024-24902: Medium severity emc recoverpoint vulnerability
Published Dec 13, 2024
·Updated
Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability leading to gaining access to unauthorized data for a limited time.
Affected Software
3 affected components
Dell RecoverPoint for Virtual Machines>=6.0.0<6.1.0
Dell RecoverPoint for Virtual Machines=6.0-sp1
Dell RecoverPoint for Virtual Machines=6.0-sp1_p1
Event History
Dec 13, 2024
CVE Published
via MITRE·02:11 PM
Data Sourced
via MITRE·02:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24902?
CVE-2024-24902 is classified as a low severity vulnerability.
2
How do I fix CVE-2024-24902?
To mitigate CVE-2024-24902, update Dell RecoverPoint for Virtual Machines to version 6.1.0 or later.
3
What type of vulnerability is CVE-2024-24902?
CVE-2024-24902 is an improper access control vulnerability.
4
Who could exploit CVE-2024-24902?
A low privileged local attacker could potentially exploit CVE-2024-24902.
5
What could be the impact of CVE-2024-24902?
Exploitation of CVE-2024-24902 could lead to unauthorized access to sensitive data for a limited time.