Impact
Critical
Details
Proprietary Code CVE |
Description |
CVSS Base score |
CVSS Vector String |
CVE-2022-34372 |
Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality |
9.8 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Proprietary Code CVE |
Description |
CVSS Base score |
CVSS Vector String |
CVE-2022-34372 |
Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality |
9.8 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.
Product |
Affected Versions |
Updated Versions |
Link to update |
Cyber Recovery |
Versions before 19.11.0.2 |
19.11.0.2 |
Cyber Recovery Downloads |
NOTE: Third-party vulnerabilities pertain to Golang packages and Cyber Recovery Docker containers. The proprietary vulnerability pertains to Cyber Recovery software on management host.
Product |
Affected Versions |
Updated Versions |
Link to update |
Cyber Recovery |
Versions before 19.11.0.2 |
19.11.0.2 |
Cyber Recovery Downloads |
NOTE: Third-party vulnerabilities pertain to Golang packages and Cyber Recovery Docker containers. The proprietary vulnerability pertains to Cyber Recovery software on management host.
Revision History
Revision | Date | Description |
1.0 | 2022-08-01 | Initial Release |
Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide
Affected Products
PowerProtect Cyber Recovery
Products
Product Security Information