CVE-2024-29173

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Server-Side Request Forgery (SSRF) vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to disclosure of information on the application or remote client.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
OR cpe:2.3:a:dell:apex_protection_storage:-:*:*:*:in-cloud:*:*:*
cpe:2.3:a:dell:apex_protection_storage:-:*:*:*:on-premises:*:*:*
cpe:2.3:h:dell:dd3300:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd6400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd6900:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9410:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9900:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9910:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:dm5500:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-06-26 03:15

Updated : 2025-02-03 15:08


NVD link : CVE-2024-29173

Mitre link : CVE-2024-29173

CVE.ORG link : CVE-2024-29173


JSON object : View

Products Affected

dell

  • dd9910
  • dm5500
  • dd9400
  • dd6900
  • data_domain_operating_system
  • dd6400
  • dd3300
  • dd9410
  • dd9900
  • apex_protection_storage
CWE
CWE-918

Server-Side Request Forgery (SSRF)