PT-2024-32935 · Dell · Dell Secure Connect Gateway (Scg) 5.0 Appliance
Published
2024-10-18
·
Updated
2024-12-13
·
CVE-2024-48016
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version 5.24
Description
The issue is related to the use of a broken or risky cryptographic algorithm, which could be exploited by a low-privileged attacker with remote access, potentially leading to information disclosure. The attacker may use exposed credentials to access the system with the privileges of the compromised account.
Recommendations
For version 5.24, patch immediately to address the vulnerability and review encryption practices to ensure the use of secure cryptographic algorithms. As a temporary workaround, consider restricting access to sensitive data and reviewing account privileges to minimize the risk of exploitation.
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Secure Connect Gateway (Scg) 5.0 Appliance