VYPR

Powerprotect Cyber Recovery

by Dell

CVEs (8)

  • CVE-2022-34372CriSep 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter…

  • CVE-2023-32465HigJun 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability. An attacker could potentially exploit this vulnerability, leading to unauthorized admin access to the Cyber Recovery application. Exploitation may lead to complete system takeover by an…

  • CVE-2022-32481HigJul 7, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appliance deployments. A lower-privileged authenticated user can chain docker commands to escalate privileges to root leading to complete system takeover.

  • CVE-2021-21512HigFeb 19, 2021
    risk 0.51cvss 7.9epss 0.00

    Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally authenticated high privileged Cyber Recovery user may potentially exploit this vulnerability leading to the takeover of the notification email account.

  • CVE-2026-79938HigAug 26, 2026
    risk 0.49cvss 7.6epss 0.00

    Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2026-49809MedAug 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2026-79939MedAug 26, 2026
    risk 0.38cvss 5.8epss 0.00

    Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.

  • CVE-2025-26335MedApr 11, 2025
    risk 0.38cvss 5.8epss 0.00

    Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent Data vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.