Aller au contenu

Fiche vulnérabilité

CVE-2024-22454 : faille élevée dell powerprotect data manager (CVSS 8.8)

Description

Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
13 févr. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • dell powerprotect data manager

Références

Rechercher une autre vulnérabilité dans la base CVE