PT-2024-32490 · Dell · Dell Secure Connect Gateway

Published

2024-10-18

·

Updated

2024-10-22

·

CVE-2024-47240

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Dell Secure Connect Gateway (SCG) version 5.24
Description The issue is related to incorrect default permissions, allowing a local attacker with low privileges to access the file system. This could potentially lead to gaining write access to unauthorized data and causing a version update failure condition.
Recommendations For version 5.24, patch immediately and review permission settings to resolve the issue. As a temporary workaround, consider restricting access to sensitive data and file systems to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47240

Affected Products

Dell Secure Connect Gateway