Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mw7-f37q-33mg

Опубликовано: 13 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change

Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change

EPSS

Процентиль: 43%
0.0056
Низкий

8.8 High

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change

CVSS3: 8.8
fstec
больше 2 лет назад

Уязвимость программного обеспечения централизованного управления резервным копированием и восстановлением данных Dell PowerProtect Data Manager, существующая из-за ошибки в механизме восстановления забытых паролей, позволяющая нарушителю получить несанкционированный доступ к приложению

EPSS

Процентиль: 43%
0.0056
Низкий

8.8 High

CVSS3

Дефекты

CWE-640