CVE-2023-32465

Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability. An attacker could potentially exploit this vulnerability, leading to unauthorized admin access to the Cyber Recovery application. Exploitation may lead to complete system takeover by an attacker.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:powerprotect_cyber_recovery:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:03

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000214943/dsa-2023-201-security-update-for-dell-powerprotect-cyber-recovery - Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000214943/dsa-2023-201-security-update-for-dell-powerprotect-cyber-recovery - Vendor Advisory

27 Jun 2023, 18:39

Type Values Removed Values Added
First Time Dell
Dell powerprotect Cyber Recovery
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:dell:powerprotect_cyber_recovery:*:*:*:*:*:*:*:*
References (MISC) https://www.dell.com/support/kbdoc/en-us/000214943/dsa-2023-201-security-update-for-dell-powerprotect-cyber-recovery - (MISC) https://www.dell.com/support/kbdoc/en-us/000214943/dsa-2023-201-security-update-for-dell-powerprotect-cyber-recovery - Vendor Advisory

14 Jun 2023, 15:30

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-14 14:15

Updated : 2024-11-21 08:03


NVD link : CVE-2023-32465

Mitre link : CVE-2023-32465

CVE.ORG link : CVE-2023-32465


JSON object : View

Products Affected

dell

  • powerprotect_cyber_recovery
CWE
CWE-644

Improper Neutralization of HTTP Headers for Scripting Syntax