Lucene search

K
cveDellCVE-2022-32481
HistoryJul 07, 2022 - 10:15 p.m.

CVE-2022-32481

2022-07-0722:15:08
dell
web.nvd.nist.gov
45
5
cve-2022-32481
dell powerprotect
cyber recovery
privilege escalation
vulnerability
virtual appliance
docker
system takeover

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appliance deployments. A lower-privileged authenticated user can chain docker commands to escalate privileges to root leading to complete system takeover.

Affected configurations

Nvd
Vulners
Node
dellpowerprotect_cyber_recoveryRange<19.11
VendorProductVersionCPE
dellpowerprotect_cyber_recovery*cpe:2.3:a:dell:powerprotect_cyber_recovery:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cyber Recovery",
    "vendor": "Dell",
    "versions": [
      {
        "lessThan": "19.11",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Related for CVE-2022-32481