CVE-2023-44293

MEDIUM

Dell Secure Connect Gateway 5.10.00.00-5.18.00.00 - Authenticated SQL Injection via IP Range Rest API

Title source: llm
STIX 2.1

Description

In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the product database.

Scores

CVSS v3 5.4
EPSS 0.0031
EPSS Percentile 54.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
dell/secure_connect_gateway 5.10.00.00 - 5.20.00.00
Published Feb 14, 2024
Tracked Since Feb 18, 2026