CVE-2024-48008

MEDIUM

Dell RecoverPoint for Virtual Machines 6.0.x - OS Command Injection

Title source: llm
STIX 2.1

Description

Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files that may contain sensitive information

Scores

CVSS v3 5.3
EPSS 0.0029
EPSS Percentile 52.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-78 CWE-11
Status published
Products (1)
dell/recoverpoint_for_virtual_machines 6.0 sp1 (2 CPE variants)
Published Dec 13, 2024
Tracked Since Feb 18, 2026