Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-15772


Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an uncontrolled resource consumption vulnerability. A malicious boxmgmt user may potentially be able to consume large amount of CPU bandwidth to make the system slow or to determine the existence of any system file via Boxmgmt CLI.


Published

2018-11-13T14:29:00.293

Last Modified

2024-11-21T03:51:26.520

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.1 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell emc_recoverpoint < 5.1.2.1 Yes
Application dell emc_recoverpoint_for_virtual_machines < 5.2.0.2 Yes

References