CVE-2024-24900

Published Mar 1, 2024

Last updated 8 months ago

Overview

Description
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain an improper authorization vulnerability. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized devices added to policies. Exploitation may lead to information disclosure and unauthorized access to the system.
Source
security_alert@emc.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.8
Impact score
4.2
Exploitability score
1.5
Vector string
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N
Severity
MEDIUM

Weaknesses

security_alert@emc.com
CWE-285

Social media

Hype score
Not currently trending