PT-2024-32490 · Dell · Dell Secure Connect Gateway
Published
2024-10-18
·
Updated
2024-10-22
·
CVE-2024-47240
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Dell Secure Connect Gateway (SCG) version 5.24
Description
The issue is related to incorrect default permissions, allowing a local attacker with low privileges to access the file system. This could potentially lead to gaining write access to unauthorized data and causing a version update failure condition.
Recommendations
For version 5.24, patch immediately and review permission settings to resolve the issue. As a temporary workaround, consider restricting access to sensitive data and file systems to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Secure Connect Gateway