Vulnerability Details CVE-2024-22425
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to launch a brute force attack or a dictionary attack against the RecoverPoint login form. This allows attackers to brute-force the password of valid users in an automated manner.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.0%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-22425
-
cpe:2.3:a:dell:recoverpoint_for_virtual_machines:5.3
-
cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0