跳到主要内容

超危

Dell RecoverPoint for Virtual Machines (RP4VMs)硬编码漏洞

2026-02-17 19:19:34 公开 ,2026-03-04 15:13:42 更新

  • CISA KEV
  • 关键漏洞
  • APT漏洞
  • CWE Top 25 (2023)
  • CWE Top 25 (2024)
  • 无需认证
  • 远程
  • 公开PoC
CWEs:
CWE-798 (Use of Hard-coded Credentials)
CAPEC:
CAPEC-191 (Read Sensitive Constants Within an Executable) CAPEC-70 (Try Common or Default Usernames and Passwords)
SSVC:
可利用状态:已被积极利用攻击自动化:是技术影响评估:全部 2026-02-19 12:55:35

风险信息

CVSS v3.1 向量
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v3.1 风险值
10

详细信息

漏洞类型
信任管理问题
漏洞描述
Dell RecoverPoint for Virtual Machines 6.0.3.1 HF1版本之前,其集成的Apache Tomcat管理配置 /home/kos/tomcat9/tomcat-users.xml中嵌入了硬编码的默认管理员账号和密码。可能导致未认证的远程攻击者未经授权访问底层操作系统并实现根级持久化。
修复建议
请升级Dell RecoverPoint for Virtual Machines到6.0.3.1 HF1(Hot Fix 1)或更高版本,参考链接: https://www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079 https://www.dell.com/support/kbdoc/en-us/000426742/recoverpoint-for-vms-apply-the-remediation-script-for-dsa

参考链接