CVE-2024-29168
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing potential unauthorized access and modification of application data.
Dell SCG, versiones anteriores a 5.22.00.00, contienen una vulnerabilidad de inyección SQL en la interfaz de usuario de SCG para una API REST de activos internos. Un atacante autenticado remoto podría explotar esta vulnerabilidad, lo que llevaría a la ejecución de ciertos comandos SQL en la base de datos backend de la aplicación, lo que provocaría un posible acceso no autorizado y modificación de los datos de la aplicación.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-03-18 CVE Reserved
- 2024-06-13 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Secure Connect Gateway-Application Search vendor "Dell" for product "Secure Connect Gateway-Application" | >= 5.18.00.20 <= 5.22.00.18 Search vendor "Dell" for product "Secure Connect Gateway-Application" and version " >= 5.18.00.20 <= 5.22.00.18" | en |
Affected
| ||||||
Dell Search vendor "Dell" | Secure Connect Gateway-Appliance Search vendor "Dell" for product "Secure Connect Gateway-Appliance" | >= 5.18.00.20 <= 5.22.00.18 Search vendor "Dell" for product "Secure Connect Gateway-Appliance" and version " >= 5.18.00.20 <= 5.22.00.18" | en |
Affected
|