Dell SCG Vulnerable to SQL Injection Attacks
CVE-2024-29169

8.1HIGH

Key Information:

Summary

Dell Secure Connect Gateway, prior to version 5.22.00.00, is susceptible to a SQL Injection vulnerability within its internal audit REST API. This flaw allows a remote authenticated attacker to exploit the SCG user interface, enabling them to execute arbitrary SQL commands on the backend database. Successful exploitation could lead to unauthorized access and potential modification of critical application data, posing significant risks to data integrity and confidentiality.

Affected Version(s)

Secure Connect Gateway-Appliance 5.18.00.20 <= 5.22.00.18

Secure Connect Gateway-Application 5.18.00.20 <= 5.22.00.18

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank saltedfish for reporting this issue
.