ID

VAR-202403-0456


CVE

CVE-2024-24900


TITLE

Dell's  secure connect gateway  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2024-013982

DESCRIPTION

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain an improper authorization vulnerability. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized devices added to policies. Exploitation may lead to information disclosure and unauthorized access to the system. Dell's secure connect gateway Exists in unspecified vulnerabilities.Information may be obtained and information may be tampered with. No detailed vulnerability details are currently provided

Trust: 2.16

sources: NVD: CVE-2024-24900 // JVNDB: JVNDB-2024-013982 // CNVD: CNVD-2024-20304

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-20304

AFFECTED PRODUCTS

vendor:dellmodel:secure connect gatewayscope:ltversion:5.22.00.16

Trust: 1.0

vendor:デルmodel:secure connect gatewayscope:eqversion: -

Trust: 0.8

vendor:デルmodel:secure connect gatewayscope:eqversion:5.22.00.16

Trust: 0.8

vendor:デルmodel:secure connect gatewayscope: - version: -

Trust: 0.8

vendor:dellmodel:emc secure connect gatewayscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2024-20304 // JVNDB: JVNDB-2024-013982 // NVD: CVE-2024-24900

CVSS

SEVERITY

CVSSV2

CVSSV3

security_alert@emc.com: CVE-2024-24900
value: MEDIUM

Trust: 1.0

nvd@nist.gov: CVE-2024-24900
value: HIGH

Trust: 1.0

NVD: CVE-2024-24900
value: HIGH

Trust: 0.8

CNVD: CNVD-2024-20304
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2024-20304
severity: MEDIUM
baseScore: 6.2
vectorString: AV:A/AC:L/AU:S/C:P/I:C/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 5.1
impactScore: 7.8
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

security_alert@emc.com: CVE-2024-24900
baseSeverity: MEDIUM
baseScore: 5.8
vectorString: CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 1.5
impactScore: 4.2
version: 3.1

Trust: 1.0

nvd@nist.gov: CVE-2024-24900
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 2.1
impactScore: 5.2
version: 3.1

Trust: 1.0

NVD: CVE-2024-24900
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2024-20304 // JVNDB: JVNDB-2024-013982 // NVD: CVE-2024-24900 // NVD: CVE-2024-24900

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-285

Trust: 1.0

problemtype:Inappropriate authorization (CWE-285) [ others ]

Trust: 0.8

problemtype: Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-013982 // NVD: CVE-2024-24900

PATCH

title:Patch for Dell Secure Connect Gateway Authorization Issue Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/543986

Trust: 0.6

sources: CNVD: CNVD-2024-20304

EXTERNAL IDS

db:NVDid:CVE-2024-24900

Trust: 3.2

db:JVNDBid:JVNDB-2024-013982

Trust: 0.8

db:CNVDid:CNVD-2024-20304

Trust: 0.6

sources: CNVD: CNVD-2024-20304 // JVNDB: JVNDB-2024-013982 // NVD: CVE-2024-24900

REFERENCES

url:https://www.dell.com/support/kbdoc/en-us/000222330/dsa-2024-077-security-update-for-dell-secure-connect-gateway-policy-manager-vulnerabilities

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2024-24900

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2024-24900/

Trust: 0.6

sources: CNVD: CNVD-2024-20304 // JVNDB: JVNDB-2024-013982 // NVD: CVE-2024-24900

SOURCES

db:CNVDid:CNVD-2024-20304
db:JVNDBid:JVNDB-2024-013982
db:NVDid:CVE-2024-24900

LAST UPDATE DATE

2024-12-11T23:06:45.678000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-20304date:2024-04-25T00:00:00
db:JVNDBid:JVNDB-2024-013982date:2024-12-05T01:21:00
db:NVDid:CVE-2024-24900date:2024-12-04T17:57:20.727

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-20304date:2024-04-18T00:00:00
db:JVNDBid:JVNDB-2024-013982date:2024-12-05T00:00:00
db:NVDid:CVE-2024-24900date:2024-03-01T13:15:08.090