Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change
References
Configurations
History
21 Nov 2024, 08:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.dell.com/support/kbdoc/en-us/000222025/dsa-2024-061-dell-power-protect-data-manager-update-for-multiple-security-vulnerabilities - Patch, Vendor Advisory |
27 Feb 2024, 17:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.dell.com/support/kbdoc/en-us/000222025/dsa-2024-061-dell-power-protect-data-manager-update-for-multiple-security-vulnerabilities - Patch, Vendor Advisory | |
CPE | cpe:2.3:a:dell:powerprotect_data_manager:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
First Time |
Dell
Dell powerprotect Data Manager |
13 Feb 2024, 08:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-13 08:16
Updated : 2024-11-21 08:56
NVD link : CVE-2024-22454
Mitre link : CVE-2024-22454
CVE.ORG link : CVE-2024-22454
JSON object : View
Products Affected
dell
- powerprotect_data_manager
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password