CVE-2024-22425

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 16, 2024
CWE ID 307

Summary

CVE-2024-22425 is a vulnerability affecting Dell RecoverPoint for Virtual Machines 5.3.x. The issue enables an unauthenticated remote attacker to launch a brute force or dictionary attack against the RecoverPoint login form. By doing so, they can potentially gain access to valid user accounts in an automated manner. This vulnerability poses a significant risk, as attackers can exploit it to bypass authentication and gain unauthorized access to protected virtual machine data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share