Dell Data Domain SQL Injection Vulnerability Affects Data Security
CVE-2024-29174

4.4MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
26 June 2024

Summary

Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized access to application data.

Affected Version(s)

PowerProtect DD 7.0 <= 7.13

PowerProtect DD 7.8 <= 7.13

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.