Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4vx6-fgh9-hr42

Опубликовано: 02 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality

Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality

EPSS

Процентиль: 83%
0.01857
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость программного средства защиты данных Cyber Recovery, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить доступ к API-интерфейсу

EPSS

Процентиль: 83%
0.01857
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287