Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to unauthorized data.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    04 Feb 2025, 15:53
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities - Vendor Advisory | |
| CWE | CWE-798 | |
| CPE | cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1:*:*:*:*:*:* cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1_p1:*:*:*:*:*:*  | 
|
| Summary | 
        
        
  | 
|
| First Time | 
        
        Dell recoverpoint For Virtual Machines
         Dell  | 
13 Dec 2024, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-12-13 14:15
Updated : 2025-03-13 16:15
NVD link : CVE-2024-48007
Mitre link : CVE-2024-48007
CVE.ORG link : CVE-2024-48007
JSON object : View
Products Affected
                dell
- recoverpoint_for_virtual_machines
 
CWE
                
                    
                        
                        CWE-798
                        
            Use of Hard-coded Credentials
