SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-32465

Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability.

HIGH 8.8EPSS 0.73%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability. An attacker could potentially exploit this vulnerability, leading to unauthorized admin access to the Cyber Recovery application. Exploitation may lead to complete system takeover by an attacker.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.73% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-644
Affected
dell/powerprotect cyber recovery
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.