CVE-2024-29176

Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
OR cpe:2.3:a:dell:apex_protection_storage:-:*:*:*:in-cloud:*:*:*
cpe:2.3:a:dell:apex_protection_storage:-:*:*:*:on-premises:*:*:*
cpe:2.3:h:dell:dd3300:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd6400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd6900:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9410:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9900:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9910:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:dm5500:-:*:*:*:*:*:*:*

History

30 Oct 2024, 14:15

Type Values Removed Values Added
Summary Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a buffer overflow vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to an application crash or execution of arbitrary code on the vulnerable application's underlying operating system with privileges of the vulnerable application. Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

10 Oct 2024, 12:04

Type Values Removed Values Added
First Time Dell dd9910
Dell dd6400
Dell apex Protection Storage
Dell dm5500
Dell dd6900
Dell dd9400
Dell dd3300
Dell dd9410
Dell dd9900
CWE CWE-119 CWE-787
CPE cpe:2.3:a:dell:apex_protection_storage:-:*:*:*:on-premises:*:*:*
cpe:2.3:h:dell:dd9400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dm5500:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9910:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd6400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9410:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9900:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd6900:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd3300:-:*:*:*:*:*:*:*
cpe:2.3:a:dell:apex_protection_storage:-:*:*:*:in-cloud:*:*:*

23 Sep 2024, 21:11

Type Values Removed Values Added
First Time Dell data Domain Operating System
Dell
CPE cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
CWE CWE-788 CWE-119
References () https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

26 Jun 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-26 03:15

Updated : 2024-10-30 14:15


NVD link : CVE-2024-29176

Mitre link : CVE-2024-29176


JSON object : View

Products Affected

dell

  • dm5500
  • dd9410
  • dd6900
  • dd9900
  • dd6400
  • apex_protection_storage
  • dd3300
  • dd9910
  • data_domain_operating_system
  • dd9400
CWE
CWE-787

Out-of-bounds Write