CVE-2024-29174: Dell Data Domain Operating System
Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized access to application data.
Affected products
- Dell Data Domain Operating System: before 7.7.5.40 (fixed in 7.7.5.40); from 7.8.0.0, before 7.10.1.30 (fixed in 7.10.1.30); from 7.11.0.0, before 7.13.1.0 (fixed in 7.13.1.0)
Published 2024-06-26. Last modified 2026-06-17.