CVE-2024-28969

MEDIUM

Dell Secure Connect Gateway 5.18.00.20-5.22.00.18 - Improper Access Control in Internal Update REST API

Title source: llm
STIX 2.1

Description

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources.

Scores

CVSS v3 4.3
EPSS 0.0122
EPSS Percentile 79.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
dell/secure_connect_gateway 5.18.00.20 - 5.22.00.18
Published Jun 13, 2024
Tracked Since Feb 18, 2026