Lucene search

K
vulnrichmentDellVULNRICHMENT:CVE-2024-29177
HistoryJun 26, 2024 - 2:46 a.m.

CVE-2024-29177

2024-06-2602:46:55
CWE-532
dell
github.com
2
dell powerprotect
temporary sensitive information
vulnerability
unauthorized access

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

14.7%

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive information vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the reuse of disclosed information to gain unauthorized access to the application report.

CNA Affected

[
  {
    "vendor": "Dell",
    "product": "PowerProtect DD",
    "versions": [
      {
        "status": "affected",
        "version": "7.0",
        "versionType": "semver",
        "lessThanOrEqual": "7.13"
      },
      {
        "status": "affected",
        "version": "N/A",
        "lessThan": "2.7.7",
        "versionType": "semver"
      },
      {
        "status": "affected",
        "version": "N/A",
        "lessThan": "5.16.0.0",
        "versionType": "semver"
      },
      {
        "status": "affected",
        "version": "7.8",
        "versionType": "semver",
        "lessThanOrEqual": "7.13"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

14.7%

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-29177