PT-2024-20652 · Dell · Dell Secure Connect Gateway (Scg) Policy Manager
Juust4
·
Published
2024-03-01
·
Updated
2025-05-20
·
CVE-2024-24900
CVSS v3.1
7.3
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Dell Secure Connect Gateway (SCG) Policy Manager, all versions
Description
The issue is related to an improper authorization vulnerability. An attacker with low privileges on an adjacent network could potentially exploit this, leading to unauthorized devices being added to policies. This may result in information disclosure and unauthorized access to the system.
Recommendations
For all versions, update to a version that includes a fix for the improper authorization vulnerability, as no specific workaround or mitigation has been provided for this issue.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Secure Connect Gateway (Scg) Policy Manager