vendor:
RecoverPoint
by:
Paul Taylor
9.8
CVSS
CRITICAL
Local Root Command Execution
78
CWE
Product Name: RecoverPoint
Affected Version From: All versions before RP 5.1.2, and all versions before RP4VMs 5.1.1.3
Affected Version To: 5.1.1.2
Patch Exists: YES
Related CWE: CVE-2018-1235
CPE: a:dell:emc_recoverpoint
Platforms Tested: RP4VMs 5.1.1.2, RP 5.1.SP1.P2
2018
Dell EMC RecoverPoint < 5.1.2 - Local Root Command Execution
An OS command injection vulnerability exists in the mechanism which processes usernames which are presented for authentication, allowing unauthenticated root access via tty console login.
Mitigation:
Apply the patch provided by Dell EMC to upgrade to version 5.1.2 or later.