Fiche vulnérabilité
CVE-2024-48007 : faille critique dell recoverpoint for virtual machines (CVSS 9.8)
Description
Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to unauthorized data.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 13 déc. 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- dell recoverpoint for virtual machines