CVE-2023-44294
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of Collection Rest API.
This issue may potentially lead to unintentional information disclosure from the product database.
En la aplicación Dell Secure Connect Gateway y el dispositivo Secure Connect Gateway (entre v5.10.00.00 y v5.18.00.00), se identificó un problema de seguridad en el que un usuario malintencionado con una sesión de usuario válida puede inyectar contenido malicioso en los filtros API de resto de colección. Este problema puede provocar potencialmente la divulgación involuntaria de información de la base de datos del producto.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-09-28 CVE Reserved
- 2024-02-14 CVE Published
- 2024-08-14 CVE Updated
- 2024-10-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Secure Connect Gateway-Application Search vendor "Dell" for product "Secure Connect Gateway-Application" | >= v5.10.00.00 <= v5.18.00.00 Search vendor "Dell" for product "Secure Connect Gateway-Application" and version " >= v5.10.00.00 <= v5.18.00.00" | en |
Affected
| ||||||
Dell Search vendor "Dell" | Secure Connect Gateway-Appliance Search vendor "Dell" for product "Secure Connect Gateway-Appliance" | >= v5.10.00.00 <= v5.18.00.00 Search vendor "Dell" for product "Secure Connect Gateway-Appliance" and version " >= v5.10.00.00 <= v5.18.00.00" | en |
Affected
|