DSA-2021-038: Dell EMC PowerProtect Cyber Recovery Security Update for Unintended Information Disclosure
Summary: Dell EMC PowerProtect Cyber Recovery contains remediation for unintended information disclosure that may be exploited by malicious users to compromise the affected system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
High
Details
| Proprietary Code CVE(s) | Description | CVSSBase Score | CVSS Vector String |
| CVE-2021-21512 | Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally authenticated high privileged Cyber Recovery user may potentially exploit this vulnerability leading to the takeover of the notification email account. | 7.9 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
| Proprietary Code CVE(s) | Description | CVSSBase Score | CVSS Vector String |
| CVE-2021-21512 | Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally authenticated high privileged Cyber Recovery user may potentially exploit this vulnerability leading to the takeover of the notification email account. | 7.9 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Affected Products & Remediation
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2021-21512 | PowerProtect Cyber Recovery | 19.7.0.1 | 19.7.0.2 | Contact Dell EMC Customer Support |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2021-21512 | PowerProtect Cyber Recovery | 19.7.0.1 | 19.7.0.2 | Contact Dell EMC Customer Support |
Workarounds & Mitigations
None
Revision History
| Revision | Date | Description |
| 1.0 | 2021-02-17 | Initial Release |
| 1.1 | 2021-02-18 | Minor update |
Related Information
Legal Disclaimer
Affected Products
PowerProtect Cyber Recovery, Product Security InformationArticle Properties
Article Number: 000183169
Article Type: Dell Security Advisory
Last Modified: 20 Feb 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.