CVE-2023-44284

MEDIUM

Dell PowerProtect DD < 7.13.0.10 - SQL Injection

Title source: llm
STIX 2.1

Description

Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data.

Scores

CVSS v3 4.3
EPSS 0.0023
EPSS Percentile 46.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (9)
dell/apex_protection_storage < 6.2.1.110
dell/emc_data_domain_os < 6.2.1.110
dell/emc_data_domain_os 7.10 - 7.10.1.15
dell/emc_data_domain_os 7.7 - 7.7.5.25
dell/powerprotect_data_domain < 6.2.1.110
dell/powerprotect_data_domain_management_center < 6.2.1.110
dell/powerprotect_data_domain_management_center 7.10 - 7.10.1.15
dell/powerprotect_data_domain_management_center 7.7 - 7.7.5.25
dell/powerprotect_data_protection < 2.7.6
Published Dec 14, 2023
Tracked Since Feb 18, 2026