CVE-2024-28965

MEDIUM

Dell Secure Connect Gateway 5.18.00.20-5.22.00.18 - Improper Access Control via Internal Enable REST API

Title source: llm
STIX 2.1

Description

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain Internal APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state.

Scores

CVSS v3 5.4
EPSS 0.0140
EPSS Percentile 80.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
dell/secure_connect_gateway 5.18.00.20 - 5.22.00.18
Published Jun 13, 2024
Tracked Since Feb 18, 2026