CVE-2016-6649

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
03/02/2017
Last modified:
20/04/2025

Description

EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface and escalate his privileges to root.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:emc:recoverpoint:*:*:*:*:*:*:*:* 4.4.1.0 (including)
cpe:2.3:a:emc:recoverpoint_for_virtual_machines:*:*:*:*:*:*:*:* 4.0 (including)