#VU12995 Remote code execution in RecoverPoint - CVE-2018-1235

 

#VU12995 Remote code execution in RecoverPoint - CVE-2018-1235

Published: May 23, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU12995
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2018-1235
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
RecoverPoint
Software vendor:
Dell

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to unspecified flaw. A remote attacker who has visibility of RecoverPoint on the network can execute arbitrary code on the underlying Linux operating system with root privileges.



Remediation

Update to version 5.1.2 or 5.1.1.3.

External links