CVE-2024-24900: High severity dell emc secure connect gateway policy manager vulnerability
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain an improper authorization vulnerability. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized devices added to policies. Exploitation may lead to information disclosure and unauthorized access to the system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24900?
CVE-2024-24900 is classified as a high severity vulnerability due to its potential to allow unauthorized access to system policies.
How do I fix CVE-2024-24900?
To fix CVE-2024-24900, it is recommended to update to the latest version of Dell Secure Connect Gateway Policy Manager that addresses this vulnerability.
Who is affected by CVE-2024-24900?
CVE-2024-24900 affects all versions of Dell Secure Connect Gateway Policy Manager prior to version 5.22.00.16.
What can attackers do with CVE-2024-24900?
Attackers exploiting CVE-2024-24900 can potentially add unauthorized devices to policies, leading to information disclosure.
Is CVE-2024-24900 easy to exploit?
CVE-2024-24900 can be exploited by low privileged attackers on an adjacent network, indicating a moderate level of ease for exploitation.