#VU102868 Improper Restriction of Excessive Authentication Attempts in RecoverPoint for VMs - CVE-2024-22425
Published: January 16, 2025
RecoverPoint for VMs
Dell
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to brute force/dictionary attack. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to launch a brute force attack or a dictionary attack against the RecoverPoint login form. This allows attackers to brute-force the password of valid users in an automated manner.