« Volver al listado

CVE-2024-29173

Estado: AnalizadaMedia (4.9)—

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Server-Side Request Forgery (SSRF) vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to disclosure of information on the application or remote client.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-29173",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-29173",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-06-26T13:51:50.695281Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 2.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "PowerProtect DD",
          "versions": [
            {
              "status": "affected",
              "version": "7.0",
              "versionType": "semver",
              "lessThanOrEqual": "7.13"
            },
            {
              "status": "affected",
              "version": "N/A",
              "lessThan": "2.7.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "N/A",
              "lessThan": "5.16.0.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-06-26T03:15:09.877",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Server-Side Request Forgery (SSRF) vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to disclosure of information on the application or remote client."
    },
    {
      "lang": "es",
      "value": "Dell PowerProtect DD, versiones anteriores a 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contienen una vulnerabilidad de Server Side Request Forgery (SSRF). Un atacante remoto con altos privilegios podría explotar esta vulnerabilidad, lo que llevaría a la divulgación de información sobre la aplicación o el cliente remoto."
    }
  ],
  "lastModified": "2026-06-17T07:22:33.580",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51B3D8A3-950B-4D4E-9E4D-7D1ADE791C93",
              "versionEndIncluding": "7.13",
              "versionStartIncluding": "7.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:apex_protection_storage:-:*:*:*:in-cloud:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "83DBF4F3-791C-48A2-B37E-6B3F6177B470"
            },
            {
              "criteria": "cpe:2.3:a:dell:apex_protection_storage:-:*:*:*:on-premises:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D007B2BB-082B-4D33-A6A1-77714341C75C"
            },
            {
              "criteria": "cpe:2.3:h:dell:dd3300:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AA4D9616-4482-4173-9507-6B8EC15F3521"
            },
            {
              "criteria": "cpe:2.3:h:dell:dd6400:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4A81372F-E8DC-49AB-AC12-700F76D4C2C6"
            },
            {
              "criteria": "cpe:2.3:h:dell:dd6900:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5525030D-2AA9-4AB6-8B15-D09214C1834E"
            },
            {
              "criteria": "cpe:2.3:h:dell:dd9400:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4C08E46D-6795-46DB-BA6C-548D7B8EBFA5"
            },
            {
              "criteria": "cpe:2.3:h:dell:dd9410:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F820D2BB-4773-4B2F-BC50-9474B44DB8F6"
            },
            {
              "criteria": "cpe:2.3:h:dell:dd9900:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "105F8F20-3EB3-49E7-82BE-3A5742EAA51E"
            },
            {
              "criteria": "cpe:2.3:h:dell:dd9910:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "84F58819-777E-43C1-B1EA-FFD7CDF79234"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D655A40E-7358-4E29-BDC6-8CC2E8BA1D63",
              "versionEndExcluding": "5.16.0.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:dm5500:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5B15806F-F6F1-4B26-921C-FE7620B3539F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}