Improper Authentication in Dell PowerProtect Cyber Recovery - CVE-2022-34372
Published: August 4, 2022
Vulnerability identifier: #VU66108
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-34372
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an authentication bypass. A remote attacker may potentially access and interact with the docker registry API leading to an authentication bypass and loss of integrity and confidentiality
Affected software
Dell PowerProtect Cyber Recovery
How to mitigate CVE-2022-34372
Install updates from vendor's website.
Dell PowerProtect Cyber Recovery - update to 19.11.0.2