CVE-2024-24900

MEDIUM

Dell Secure Connect Gateway - Auth Bypass

Title source: llm
STIX 2.1

Description

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain an improper authorization vulnerability. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized devices added to policies. Exploitation may lead to information disclosure and unauthorized access to the system.

Scores

CVSS v3 5.8
EPSS 0.0008
EPSS Percentile 24.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-285
Status published
Products (1)
dell/policy_manager_for_secure_connect_gateway < 5.22.00.16
Published Mar 01, 2024
Tracked Since Feb 18, 2026