CVE-2024-48008CWE-11

Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability

Medium · published December 13, 2024

CVSS v3.1
5.3
EPSS
1%
Percentile
44.9
In the wild
Unconfirmed
What it is

Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files that may contain sensitive information

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.00567 · 44.9th percentile
Weakness
CWE-11 · ASP.NET Misconfiguration: Creating Debug Binary
Published
2024-12-13T13:30Z
EPSS history
Timeline
  • 13 DEC 13:30Z
    Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability
    cvelistv5