Dell SCG Vulnerable to SQL Injection Attacks
CVE-2024-29169
8.1HIGH
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 13 June 2024
Summary
Dell Secure Connect Gateway, prior to version 5.22.00.00, is susceptible to a SQL Injection vulnerability within its internal audit REST API. This flaw allows a remote authenticated attacker to exploit the SCG user interface, enabling them to execute arbitrary SQL commands on the backend database. Successful exploitation could lead to unauthorized access and potential modification of critical application data, posing significant risks to data integrity and confidentiality.
Affected Version(s)
Secure Connect Gateway-Appliance 5.18.00.20 <= 5.22.00.18
Secure Connect Gateway-Application 5.18.00.20 <= 5.22.00.18
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank saltedfish for reporting this issue