HIGH🇵🇱 Wersja polska

CVE-2022-32481

CVSS 7.8v3.1pub. 2022-07-07upd. 2024-11-21

Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appliance deployments. A lower-privileged authenticated user can chain docker commands to escalate privileges to root leading to complete system takeover.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Dell Powerprotect Cyber Recovery

    APP
    Dell
    < 19.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPEContainer
CWE
References

Related vulnerabilities

CVE-2022-34372CRITICAL9.8PL ✓same product

Dell PowerProtect Cyber Recovery — Authentication Bypass w Docker Registry API

CVE-2026-79938HIGH7.6same product

Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A ...

CVE-2023-32465HIGH8.8same product

Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability. An attacker could potenti...

CVE-2026-49809MEDIUM6.5same product

Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Eleme...

CVE-2026-79939MEDIUM5.8same product

Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vu...