HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-32465

CVSS 8.8v3.1pub. 2023-06-14upd. 2024-11-21

Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability. An attacker could potentially exploit this vulnerability, leading to unauthorized admin access to the Cyber Recovery application. Exploitation may lead to complete system takeover by an attacker.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Dell Powerprotect Cyber Recovery

    APP
    Dell
    19.4 – 19.13.0.2
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-34372CRITICAL9.8PL ✓same product

Dell PowerProtect Cyber Recovery — Authentication Bypass w Docker Registry API

CVE-2022-32481HIGH7.8same product

Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on vir...

CVE-2025-26335MEDIUM5.8same product

Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information ...

CVE-2026-22769CRITICAL10.0⚠ KEVPL ✓same vendor

Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)

CVE-2026-54489CRITICAL9.1PL ✓same vendor

Dell Virtual Storage Integrator — ujawnienie sesji i przejęcie konta