Dell RecoverPoint for Virtual Machines Command Execution Vulnerability

Vulnerability

A command execution vulnerability has been identified in Dell RecoverPoint for Virtual Machines versions 6.0 SP1, 6.0 SP1 P1, and 6.0 SP1 P2. This vulnerability allows a low-privileged user with local access to execute commands by running a specific binary. The executed commands can include administrative actions, such as shutting down the server or modifying configurations, which could lead to unauthorized access to data.

Impact

Exploitation of this vulnerability could allow a low-privileged user to execute commands with administrative privileges, potentially leading to unauthorized data access, server shutdowns, or disruptive configuration changes.

Remediation

Users can upgrade to Dell RecoverPoint for Virtual Machines version 6.0 SP2 or later. For more information, visit the Dell RecoverPoint for Virtual Machines Drivers page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
7.5
exploitability
3.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.