Dell Data Domain SQL Injection Vulnerability Affects Data Security

CVE-2024-29174
4.4MEDIUM

Key Information

Vendor
Dell
Status
Powerprotect Dd
Vendor
CVE Published:
26 June 2024

Summary

Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized access to application data.

Affected Version(s)

PowerProtect DD <= 7.13

PowerProtect DD <= 7.13

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.