CVE-2024-22425
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 16, 2024
CWE ID 307
Summary
CVE-2024-22425 is a vulnerability affecting Dell RecoverPoint for Virtual Machines 5.3.x. The issue enables an unauthenticated remote attacker to launch a brute force or dictionary attack against the RecoverPoint login form. By doing so, they can potentially gain access to valid user accounts in an automated manner. This vulnerability poses a significant risk, as attackers can exploit it to bypass authentication and gain unauthorized access to protected virtual machine data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.