PT-2024-22781 · Dell · Dell Powerprotect Data Domain

Published

2024-06-26

·

Updated

2024-09-23

·

CVE-2024-29175

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell PowerProtect Data Domain versions prior to 7.13.0.0 Dell PowerProtect Data Domain LTS 7.7.5.40 Dell PowerProtect Data Domain LTS 7.10.1.30
Description The issue is related to a weak cryptographic algorithm. A remote unauthenticated attacker could potentially exploit this, leading to a man-in-the-middle attack that exposes sensitive session information.
Recommendations For versions prior to 7.13.0.0, update to version 7.13.0.0 or later. For LTS 7.7.5.40, update to a version later than 7.7.5.40. For LTS 7.10.1.30, update to a version later than 7.10.1.30.

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2024-29175

Affected Products

Dell Powerprotect Data Domain