CVE-2024-24905: XSS
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24905?
CVE-2024-24905 is classified as a high severity vulnerability due to the potential for exploitation by an adjacent network high privileged attacker.
How do I fix CVE-2024-24905?
To fix CVE-2024-24905, users should update their Dell Secure Connect Gateway to versions higher than 5.22.00.16 as per the security update guidance.
What type of vulnerability is CVE-2024-24905?
CVE-2024-24905 is a Stored Cross-Site Scripting vulnerability that allows storage of malicious HTML or JavaScript in a trusted application.
Who is affected by CVE-2024-24905?
CVE-2024-24905 affects all versions of Dell Secure Connect Gateway Policy Manager, particularly those prior to 5.22.00.16.
What impact does CVE-2024-24905 have?
The impact of CVE-2024-24905 includes potential unauthorized actions carried out through the execution of stored malicious scripts.