Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change
References
Link | Resource |
---|---|
https://www.dell.com/support/kbdoc/en-us/000222025/dsa-2024-061-dell-power-protect-data-manager-update-for-multiple-security-vulnerabilities | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-02-13 08:16
Updated : 2024-02-27 17:10
NVD link : CVE-2024-22454
Mitre link : CVE-2024-22454
CVE.ORG link : CVE-2024-22454
JSON object : View
Products Affected
dell
- powerprotect_data_manager
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password