« Volver al listado

CVE-2023-44284

Estado: ModificadaMedia (4.3)—

Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-44284",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-44284",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-21T16:19:54.936040Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "PowerProtect DD",
          "versions": [
            {
              "status": "affected",
              "version": "Versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-14T16:15:46.880",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000220264/dsa-2023-412-dell-technologies-powerprotect-security-update-for-multiple-security-vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000220264/dsa-2023-412-dell-technologies-powerprotect-security-update-for-multiple-security-vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nDell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data. \n\n"
    },
    {
      "lang": "es",
      "value": "Dell PowerProtect DD, versiones anteriores a 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contienen una vulnerabilidad de inyección SQL. Un atacante remoto con pocos privilegios podría explotar esta vulnerabilidad, lo que llevaría a la ejecución de ciertos comandos SQL en la base de datos backend de la aplicación, lo que provocaría un acceso de lectura no autorizado a los datos de la aplicación."
    }
  ],
  "lastModified": "2026-06-17T06:27:17.447",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:powerprotect_data_protection:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3ECDF606-7EAF-4846-AE1F-4DDD6E4A0F9E",
              "versionEndExcluding": "2.7.6"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:dp4400:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4886295D-2A46-4AD3-8DC4-0FA212640C31"
            },
            {
              "criteria": "cpe:2.3:h:dell:dp5900:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C5D3E6F9-70B2-4347-A58B-0868395D6193"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:apex_protection_storage:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69E4E017-55A9-4E0F-A7EF-C4100B8AB1D7",
              "versionEndExcluding": "6.2.1.110"
            },
            {
              "criteria": "cpe:2.3:a:dell:apex_protection_storage:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86944363-EB13-4C55-9B54-6416B7B6D8E1",
              "versionEndExcluding": "7.10.1.15",
              "versionStartIncluding": "7.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:virtual:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E55E7C34-C4A4-4E91-A1A8-CEADB6423BB1",
              "versionEndExcluding": "6.2.1.110"
            },
            {
              "criteria": "cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:virtual:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0C53AB7-8C4F-4B92-A229-363D39A6CEDC",
              "versionEndExcluding": "7.12.0.0",
              "versionStartIncluding": "7.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:powerprotect_data_domain_management_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9540FB1D-8ACB-4697-9F64-0CC6EB81706E",
              "versionEndExcluding": "6.2.1.110"
            },
            {
              "criteria": "cpe:2.3:a:dell:powerprotect_data_domain_management_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F4CE859-62A1-4DB5-B986-FC2943D66A5A",
              "versionEndExcluding": "7.13.0.10",
              "versionStartIncluding": "7.0"
            },
            {
              "criteria": "cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF1B175C-0AF1-42C1-9F84-47BC260C3819",
              "versionEndExcluding": "6.2.1.110"
            },
            {
              "criteria": "cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0BD632A5-142D-4FA3-85FE-EAC079EFA8D8",
              "versionEndExcluding": "7.12.0.0",
              "versionStartIncluding": "7.0"
            },
            {
              "criteria": "cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:lts2022:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BADA4FAB-B4E2-43D8-8BE6-960B333D8CB8",
              "versionEndExcluding": "7.7.5.25",
              "versionStartIncluding": "7.7"
            },
            {
              "criteria": "cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:lts2023:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "585FCF80-A59C-4070-9D7D-8B707983A6ED",
              "versionEndExcluding": "7.10.1.15",
              "versionStartIncluding": "7.10"
            },
            {
              "criteria": "cpe:2.3:o:dell:powerprotect_data_domain_management_center:*:*:*:*:lts2022:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D0424A4-BA46-4CF3-8704-CC894EF2B194",
              "versionEndExcluding": "7.7.5.25",
              "versionStartIncluding": "7.7"
            },
            {
              "criteria": "cpe:2.3:o:dell:powerprotect_data_domain_management_center:*:*:*:*:lts2023:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EDE4E1BC-05DC-4B31-B0C1-97DBA2BE9CE9",
              "versionEndExcluding": "7.10.1.15",
              "versionStartIncluding": "7.10"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:dd3300:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AA4D9616-4482-4173-9507-6B8EC15F3521"
            },
            {
              "criteria": "cpe:2.3:h:dell:dd6400:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4A81372F-E8DC-49AB-AC12-700F76D4C2C6"
            },
            {
              "criteria": "cpe:2.3:h:dell:dd6900:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5525030D-2AA9-4AB6-8B15-D09214C1834E"
            },
            {
              "criteria": "cpe:2.3:h:dell:dd9400:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4C08E46D-6795-46DB-BA6C-548D7B8EBFA5"
            },
            {
              "criteria": "cpe:2.3:h:dell:dd9900:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "105F8F20-3EB3-49E7-82BE-3A5742EAA51E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}