CVE-2016-6648

Severity CVSS v4.0:
Pending analysis
Type:
CWE-275 Permission Issues
Publication date:
03/02/2017
Last modified:
20/04/2025

Description

EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file. A malicious administrator with configuration privileges may access this sensitive system file and compromise the affected system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:emc:recoverpoint:*:*:*:*:*:*:*:* 4.4.1.0 (including)
cpe:2.3:a:emc:recoverpoint_for_virtual_machines:*:*:*:*:*:*:*:* 4.0 (including)