CVE-2016-6648
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file.
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file. A malicious administrator with configuration privileges may access this sensitive system file and compromise the affected system.
- CVSS 3.0
- 4.4 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-275
- Affected
- dell/recoverpoint for virtual machines · emc/recoverpoint
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/archive/1/540058/30/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95821Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037727Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/540058/30/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95821Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037727Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.