Dell SCG Vulnerable to SQL Injection Attacks
CVE-2024-29168

8.8HIGH

Key Information:

Summary

The vulnerability in the Dell Secure Connect Gateway (SCG) allows remote authenticated attackers to exploit a SQL injection flaw in the SCG UI's internal assets REST API. By injecting certain SQL commands, an attacker could manipulate the backend database, potentially leading to unauthorized access and modifications of application data. Users of versions prior to 5.22.00.00 are particularly at risk and are advised to implement security measures promptly.

Affected Version(s)

Secure Connect Gateway-Appliance 5.18.00.20 <= 5.22.00.18

Secure Connect Gateway-Application 5.18.00.20 <= 5.22.00.18

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank saltedfish for reporting this issue
.