Improper Authentication in Dell PowerProtect Cyber Recovery - CVE-2022-34372

 

Improper Authentication in Dell PowerProtect Cyber Recovery - CVE-2022-34372

Published: August 4, 2022


Vulnerability identifier: #VU66109
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-34372
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an authentication bypass. A remote attacker may potentially access and interact with the docker registry API leading to an authentication bypass and loss of integrity and confidentiality


Affected software

Dell PowerProtect Cyber Recovery

How to mitigate CVE-2022-34372

Install updates from vendor's website.

Dell PowerProtect Cyber Recovery - update to 19.11.0.2

External References

Related Security Bulletins