CVE-2024-29176

Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
OR cpe:2.3:a:dell:apex_protection_storage:-:*:*:*:in-cloud:*:*:*
cpe:2.3:a:dell:apex_protection_storage:-:*:*:*:on-premises:*:*:*
cpe:2.3:h:dell:dd3300:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd6400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd6900:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9410:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9900:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9910:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:dm5500:-:*:*:*:*:*:*:*

History

30 Oct 2024, 14:15

Type Values Removed Values Added
Summary Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a buffer overflow vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to an application crash or execution of arbitrary code on the vulnerable application's underlying operating system with privileges of the vulnerable application. Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

10 Oct 2024, 12:04

Type Values Removed Values Added
CPE cpe:2.3:a:dell:apex_protection_storage:-:*:*:*:on-premises:*:*:*
cpe:2.3:h:dell:dd9400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dm5500:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9910:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd6400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9410:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9900:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd6900:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd3300:-:*:*:*:*:*:*:*
cpe:2.3:a:dell:apex_protection_storage:-:*:*:*:in-cloud:*:*:*
First Time Dell dd9910
Dell dd6400
Dell apex Protection Storage
Dell dm5500
Dell dd6900
Dell dd9400
Dell dd3300
Dell dd9410
Dell dd9900
CWE CWE-119 CWE-787

23 Sep 2024, 21:11

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-788 CWE-119
CPE cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
First Time Dell data Domain Operating System
Dell
References () https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities - Vendor Advisory

26 Jun 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-26 03:15

Updated : 2024-10-30 14:15


NVD link : CVE-2024-29176

Mitre link : CVE-2024-29176


JSON object : View

Products Affected

dell

  • dm5500
  • dd9410
  • dd6900
  • dd9900
  • dd6400
  • apex_protection_storage
  • dd3300
  • dd9910
  • data_domain_operating_system
  • dd9400
CWE
CWE-787

Out-of-bounds Write