PT-2024-32935 · Dell · Dell Secure Connect Gateway (Scg) 5.0 Appliance

Published

2024-10-18

·

Updated

2024-12-13

·

CVE-2024-48016

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version 5.24
Description The issue is related to the use of a broken or risky cryptographic algorithm, which could be exploited by a low-privileged attacker with remote access, potentially leading to information disclosure. The attacker may use exposed credentials to access the system with the privileges of the compromised account.
Recommendations For version 5.24, patch immediately to address the vulnerability and review encryption practices to ensure the use of secure cryptographic algorithms. As a temporary workaround, consider restricting access to sensitive data and reviewing account privileges to minimize the risk of exploitation.

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2024-48016

Affected Products

Dell Secure Connect Gateway (Scg) 5.0 Appliance