CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2022-34372

CVSS 9.8v3.1pub. 2022-09-01upd. 2024-11-21

Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dell Powerprotect Cyber Recovery

    APP
    Dell
    < 19.11.0.2
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth BypassContainer
CWE
References

Related vulnerabilities

CVE-2026-79938HIGH7.6same product

Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A ...

CVE-2023-32465HIGH8.8same product

Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability. An attacker could potenti...

CVE-2022-32481HIGH7.8same product

Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on vir...

CVE-2026-49809MEDIUM6.5same product

Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Eleme...

CVE-2026-79939MEDIUM5.8same product

Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vu...