CVE-2024-38488
CVSS V2 None
CVSS V3 None
Description
Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the RecoverPoint login form and a complete system compromise.
This allows attackers to brute-force the password of valid users in an automated manner.
Overview
- CVE ID
- CVE-2024-38488
- Assigner
- dell
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-12-13T14:06:25.845Z
- Last Modified Date
- 2024-12-13T20:38:43.920Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities | vendor-advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-38488 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38488 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-12-14 14:08:48 | Added to TrackCVE |