Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the RecoverPoint login form and a complete system compromise.
This allows attackers to brute-force the password of valid users in an automated manner.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Dec 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 13 Dec 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the RecoverPoint login form and a complete system compromise. This allows attackers to brute-force the password of valid users in an automated manner. | |
Weaknesses | CWE-307 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: dell
Published: 2024-12-13T14:06:25.845Z
Updated: 2024-12-13T20:38:43.920Z
Reserved: 2024-06-18T01:53:34.136Z
Link: CVE-2024-38488
Vulnrichment
Updated: 2024-12-13T19:09:46.215Z
NVD
Status : Received
Published: 2024-12-13T14:15:21.993
Modified: 2024-12-13T14:15:21.993
Link: CVE-2024-38488
Redhat
No data.