PT-2024-2797 · Dell · Dell Unity

Published

2024-02-12

·

Updated

2024-02-16

·

CVE-2024-22221

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell Unity versions prior to 5.4
Description The issue is related to a lack of protection of the SQL query structure in the Dell Unity Operating Environment, which can be exploited by an authenticated attacker to expose sensitive information. This is a SQL Injection vulnerability that could allow a remote attacker to disclose protected information.
Recommendations For versions prior to 5.4, update to version 5.4 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and limiting the privileges of authenticated users to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-02936
CVE-2024-22221

Affected Products

Dell Unity