CVE-2016-6649
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface…
Does this matter?
Lower severity and a low EPSS score (0.89%). Track it; it rarely justifies an emergency change on its own.
Description
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface and escalate his privileges to root.
- CVSS 3.0
- 6.7 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- dell/recoverpoint for virtual machines · emc/recoverpoint
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/archive/1/540058/30/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95821Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037727Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/540058/30/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95821Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037727Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.