Dell SCG Vulnerable to SQL Injection Attacks
CVE-2024-29168
8.8HIGH
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 13 June 2024
Summary
The vulnerability in the Dell Secure Connect Gateway (SCG) allows remote authenticated attackers to exploit a SQL injection flaw in the SCG UI's internal assets REST API. By injecting certain SQL commands, an attacker could manipulate the backend database, potentially leading to unauthorized access and modifications of application data. Users of versions prior to 5.22.00.00 are particularly at risk and are advised to implement security measures promptly.
Affected Version(s)
Secure Connect Gateway-Appliance 5.18.00.20 <= 5.22.00.18
Secure Connect Gateway-Application 5.18.00.20 <= 5.22.00.18
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank saltedfish for reporting this issue