vendor:
RecoverPoint
by:
Paul Taylor
9.8
CVSS
CRITICAL
OS command injection
78
CWE
Product Name: RecoverPoint
Affected Version From: All versions before RP 5.1.2, and all versions before RP4VMs 5.1.1.3
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2018-1235
CPE: a:dell_emc:recoverpoint
Platforms Tested: RP4VMs 5.1.1.2, RP 5.1.SP1.P2
2018
Dell EMC RecoverPoint < 5.1.2 - Remote Root Command Execution
An OS command injection vulnerability exists in the mechanism which processes usernames which are presented for authentication, allowing unauthenticated root access via the ssh service.
Mitigation:
Upgrade to Dell EMC RecoverPoint version 5.1.2 or higher.