{"api_version":"1","generated_at":"2026-07-23T14:28:27+00:00","cve":"CVE-2023-32465","urls":{"html":"https://cve.report/CVE-2023-32465","api":"https://cve.report/api/cve/CVE-2023-32465.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-32465","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-32465"},"summary":{"title":"CVE-2023-32465","description":"Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability. An attacker could potentially exploit this vulnerability, leading to unauthorized admin access to the Cyber Recovery application. Exploitation may lead to complete system takeover by an attacker.","state":"PUBLIC","assigner":"secure@dell.com","published_at":"2023-06-14 14:15:00","updated_at":"2023-06-27 18:39:00"},"problem_types":["CWE-644"],"metrics":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000214943/dsa-2023-201-security-update-for-dell-powerprotect-cyber-recovery","name":"https://www.dell.com/support/kbdoc/en-us/000214943/dsa-2023-201-security-update-for-dell-powerprotect-cyber-recovery","refsource":"MISC","tags":[],"title":"Access Denied","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-32465","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32465","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"32465","vulnerable":"1","versionEndIncluding":"19.13.0.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dell","cpe5":"powerprotect_cyber_recovery","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-32465","ASSIGNER":"secure@dell.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"\nDell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability. An attacker could potentially exploit this vulnerability, leading to unauthorized admin access to the Cyber Recovery application. Exploitation may lead to complete system takeover by an attacker.\n\n"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax","cweId":"CWE-644"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Dell","product":{"product_data":[{"product_name":"PowerProtect Cyber Recovery","version":{"version_data":[{"version_affected":"=","version_value":"19.4 through 19.13.0.2"}]}}]}}]}},"references":{"reference_data":[{"url":"https://www.dell.com/support/kbdoc/en-us/000214943/dsa-2023-201-security-update-for-dell-powerprotect-cyber-recovery","refsource":"MISC","name":"https://www.dell.com/support/kbdoc/en-us/000214943/dsa-2023-201-security-update-for-dell-powerprotect-cyber-recovery"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"discovery":"UNKNOWN"},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}]}},"nvd":{"publishedDate":"2023-06-14 14:15:00","lastModifiedDate":"2023-06-27 18:39:00","problem_types":["CWE-644"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:dell:powerprotect_cyber_recovery:*:*:*:*:*:*:*:*","versionStartIncluding":"19.4","versionEndIncluding":"19.13.0.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}