CVE-2024-29169: SQL Injection
Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing potential unauthorized access and modification of application data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29169?
CVE-2024-29169 is considered a high-severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2024-29169?
To mitigate CVE-2024-29169, upgrade Dell SCG to version 5.22.00.00 or higher.
Who is affected by CVE-2024-29169?
CVE-2024-29169 affects users of Dell SCG versions prior to 5.22.00.00.
What type of vulnerability is CVE-2024-29169?
CVE-2024-29169 is classified as a SQL Injection vulnerability in the SCG UI.
What could an attacker achieve by exploiting CVE-2024-29169?
An attacker exploiting CVE-2024-29169 could execute arbitrary SQL commands on the backend database.