Vulnerability Description
Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Powerprotect Cyber Recovery | < 19.11.0.2 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/en-us/000201970/dsa-2022-196-dell-emc-cyber-rPatchVendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000201970/dsa-2022-196-dell-emc-cyber-rPatchVendor Advisory
FAQ
What is CVE-2022-34372?
CVE-2022-34372 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registr...
How severe is CVE-2022-34372?
CVE-2022-34372 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-34372?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Powerprotect Cyber Recovery.