CVE-2022-32481
HIGHDell PowerProtect Cyber Recovery < 19.11 - Authenticated Privilege Escalation via Docker Command Chaining
Title source: llmDescription
Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appliance deployments. A lower-privileged authenticated user can chain docker commands to escalate privileges to root leading to complete system takeover.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://support.emc.com/kb/000201213
Scores
CVSS v3
7.8
EPSS
0.0004
EPSS Percentile
13.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (1)
dell/powerprotect_cyber_recovery
< 19.11
Published
Jul 07, 2022
Tracked Since
Feb 18, 2026