Dell SCG Vulnerable to SQL Injection Attacks
CVE-2024-29168
Key Information:
- Vendor
Dell
- Vendor
- CVE Published:
- 13 June 2024
What is CVE-2024-29168?
The vulnerability in the Dell Secure Connect Gateway (SCG) allows remote authenticated attackers to exploit a SQL injection flaw in the SCG UI's internal assets REST API. By injecting certain SQL commands, an attacker could manipulate the backend database, potentially leading to unauthorized access and modifications of application data. Users of versions prior to 5.22.00.00 are particularly at risk and are advised to implement security measures promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Secure Connect Gateway-Appliance 5.18.00.20 <= 5.22.00.18
Secure Connect Gateway-Application 5.18.00.20 <= 5.22.00.18
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved