Executive brief
Dell RecoverPoint for Virtual Machines, a disaster recovery solution for virtualized environments, contains a vulnerability where administrative credentials are hard-coded into the software. An attacker who knows these credentials can remotely log into the system without any prior authorization. This allows them to take full control of the underlying operating system, potentially leading to permanent access, data theft, or disruption of recovery operations. This vulnerability has been observed being exploited in the wild.
Technical details
The vulnerability (CWE-798) exists in Dell RecoverPoint for Virtual Machines (RP4VMs) due to the use of hard-coded credentials. An unauthenticated remote attacker with knowledge of these credentials can exploit the flaw over the network without any user interaction. Successful exploitation grants the attacker unauthorized access to the underlying operating system with root privileges, enabling long-term persistence. The vulnerability has been confirmed as exploited in the wild (zero-day). Dell has released version 6.0.3.1 HF1 to address this issue.
Affected products
- Dell RecoverPoint for Virtual Machines (RP4VMs) Prior to 6.0.3.1 HF1
Timeline
- 2026-02-17: disclosed: Initial disclosure by Dell
- 2026-02-18: advisory: NVD publication and CISA KEV addition
- 2026-02-18: exploited: Confirmed exploitation in the wild reported by CISA and Google Cloud/Mandiant
- 2026-02-18: patched: Remediation available in version 6.0.3.1 HF1