#VU96280 SQL injection in Dell Secure Connect Gateway - CVE-2024-29168

 

#VU96280 SQL injection in Dell Secure Connect Gateway - CVE-2024-29168

Published: August 21, 2024


Vulnerability identifier: #VU96280
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-29168
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Dell Secure Connect Gateway
Software vendor:
Dell

Description

The vulnerability allows a remote user to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing potential unauthorized access and modification of application data.


Remediation

Install update from vendor's website.

External links