Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability. An attacker could potentially exploit this vulnerability, leading to unauthorized admin access to the Cyber Recovery application. Exploitation may lead to complete system takeover by an attacker.
References
Configurations
History
21 Nov 2024, 08:03
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.dell.com/support/kbdoc/en-us/000214943/dsa-2023-201-security-update-for-dell-powerprotect-cyber-recovery - Vendor Advisory |
27 Jun 2023, 18:39
Type | Values Removed | Values Added |
---|---|---|
First Time |
Dell
Dell powerprotect Cyber Recovery |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CPE | cpe:2.3:a:dell:powerprotect_cyber_recovery:*:*:*:*:*:*:*:* | |
References | (MISC) https://www.dell.com/support/kbdoc/en-us/000214943/dsa-2023-201-security-update-for-dell-powerprotect-cyber-recovery - Vendor Advisory |
14 Jun 2023, 15:30
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-14 14:15
Updated : 2024-11-21 08:03
NVD link : CVE-2023-32465
Mitre link : CVE-2023-32465
CVE.ORG link : CVE-2023-32465
JSON object : View
Products Affected
dell
- powerprotect_cyber_recovery
CWE
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax