CVE-2024-29174

MEDIUM

Dell Data Domain < 7.7.5.40 - SQL Injection

Title source: llm
STIX 2.1

Description

Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized access to application data.

Scores

CVSS v3 4.4
EPSS 0.0014
EPSS Percentile 33.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
dell/data_domain_operating_system < 7.7.5.40
Published Jun 26, 2024
Tracked Since Feb 18, 2026