CVE-2024-28968

MEDIUM

Dell Secure Connect Gateway 5.18.00.20-5.22.00.18 - Improper Access Control in REST APIs

Title source: llm
STIX 2.1

Description

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for internal email and collection settings REST APIs (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state.

Scores

CVSS v3 5.4
EPSS 0.0140
EPSS Percentile 80.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
dell/secure_connect_gateway 5.18.00.20 - 5.22.00.18
Published Jun 13, 2024
Tracked Since Feb 18, 2026