DSA-2022-196: Dell Cyber Recovery Security Update for Multiple Vulnerabilities
Sommaire: Dell Cyber Recovery remediation is available for multiple security vulnerabilities that may potentially be exploited by malicious users to compromise the affected system.
Cet article s’applique à
Cet article ne s’applique pas à
Cet article n’est lié à aucun produit spécifique.
Toutes les versions de produits ne sont pas identifiées dans cet article.
Impact
Critical
Détails
| Proprietary Code CVE | Description | CVSS Base score | CVSS Vector String |
| CVE-2022-34372 | Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Third-party Component | CVEs | More information |
| Debian GNU/Linux, Alpine Linux | See Release Notes | See NVD (http://nvd.nist.gov/ |
| Proprietary Code CVE | Description | CVSS Base score | CVSS Vector String |
| CVE-2022-34372 | Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Third-party Component | CVEs | More information |
| Debian GNU/Linux, Alpine Linux | See Release Notes | See NVD (http://nvd.nist.gov/ |
Produits touchés et correction
| Product | Affected Versions | Updated Versions | Link to update |
| Cyber Recovery | Versions before 19.11.0.2 | 19.11.0.2 | Cyber Recovery Downloads |
NOTE: Third-party vulnerabilities pertain to Golang packages and Cyber Recovery Docker containers. The proprietary vulnerability pertains to Cyber Recovery software on management host.
| Product | Affected Versions | Updated Versions | Link to update |
| Cyber Recovery | Versions before 19.11.0.2 | 19.11.0.2 | Cyber Recovery Downloads |
NOTE: Third-party vulnerabilities pertain to Golang packages and Cyber Recovery Docker containers. The proprietary vulnerability pertains to Cyber Recovery software on management host.
Historique de révision
| Revision | Date | Description |
| 1.0 | 2022-08-01 | Initial Release |
Renseignements connexes
Avis de non-responsabilité
Produits touchés
PowerProtect Cyber RecoveryProduits
Product Security InformationPropriétés de l’article
Numéro d’article: 000201970
Type d’article: Dell Security Advisory
Dernière modification: 19 sept. 2025
Obtenez des réponses à vos questions auprès d’autre utilisateurs de Dell
Services de soutien
Vérifiez si votre appareil est couvert par les services de soutien.