CVE-2024-24903

HIGH

Dell Policy Manager For Secure Connect Gateway < 5.22.00.16 - Password Reset Weakness

Title source: rule
STIX 2.1

Description

Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change.

Scores

CVSS v3 8.0
EPSS 0.0008
EPSS Percentile 23.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-640
Status published
Products (1)
dell/policy_manager_for_secure_connect_gateway 5.10.00.10 - 5.22.00.16
Published Mar 01, 2024
Tracked Since Feb 18, 2026