First published: Fri Dec 13 2024(Updated: )
Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the RecoverPoint login form and a complete system compromise. This allows attackers to brute-force the password of valid users in an automated manner.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RecoverPoint | >6.0.0 | |
EMC RecoverPoint | =6.0-sp1 | |
EMC RecoverPoint | =6.0-sp1_p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38488 has a medium severity rating due to its potential for exploitation in brute force or dictionary attacks.
To fix CVE-2024-38488, update Dell RecoverPoint for Virtual Machines to the latest patched version provided by Dell.
CVE-2024-38488 can be exploited through brute force or dictionary attacks targeting the RecoverPoint login form.
CVE-2024-38488 affects Dell RecoverPoint for Virtual Machines versions 6.0.0 and later up to 6.0.x.
Organizations using affected versions of Dell RecoverPoint for Virtual Machines may be at risk if exposed to network attackers.