Fiche vulnérabilité
CVE-2025-21105 : faille élevée dell recoverpoint for virtual machines (CVSS 7.8)
Description
Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could potentially exploit this vulnerability by running the specific binary and perform any administrative action permitted by it resulting in shutting down the server, modifying the configuration leading to gain access to unauthorized data.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 20 févr. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- dell recoverpoint for virtual machines