CVE-2024-24904: XSS
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24904?
The severity of CVE-2024-24904 is classified as high due to its potential for exploitation by an adjacent network attacker.
How do I fix CVE-2024-24904?
To fix CVE-2024-24904, update the Dell Secure Connect Gateway Policy Manager to a version that is not affected by this vulnerability.
Who is affected by CVE-2024-24904?
CVE-2024-24904 affects all versions of Dell Secure Connect Gateway (SCG) Policy Manager up to version 5.22.00.16.
What type of vulnerability is CVE-2024-24904?
CVE-2024-24904 is a Stored Cross-Site Scripting (XSS) vulnerability.
What could an attacker achieve by exploiting CVE-2024-24904?
An attacker exploiting CVE-2024-24904 could store malicious HTML or JavaScript code in the trusted application, risking data integrity and user trust.