CVE-2024-38488: Dell RecoverPoint For Virtual Machines

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the RecoverPoint login form and a complete system compromise. This allows attackers to brute-force the password of valid users in an automated manner.

Affected products

  • Dell RecoverPoint For Virtual Machines: version 6.0 only

Published 2024-12-13. Last modified 2026-06-17.