ID

VAR-202406-1510


CVE

CVE-2024-28969


TITLE

Dell's  secure connect gateway  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2024-004984

DESCRIPTION

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources. Dell's secure connect gateway Exists in unspecified vulnerabilities.Information may be obtained

Trust: 1.62

sources: NVD: CVE-2024-28969 // JVNDB: JVNDB-2024-004984

AFFECTED PRODUCTS

vendor:dellmodel:secure connect gatewayscope:gteversion:5.18.00.20

Trust: 1.0

vendor:dellmodel:secure connect gatewayscope:lteversion:5.22.00.18

Trust: 1.0

vendor:デルmodel:secure connect gatewayscope:eqversion: -

Trust: 0.8

vendor:デルmodel:secure connect gatewayscope:eqversion:5.18.00.20 to 5.22.00.18

Trust: 0.8

vendor:デルmodel:secure connect gatewayscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2024-004984 // NVD: CVE-2024-28969

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-28969
value: MEDIUM

Trust: 1.0

security_alert@emc.com: CVE-2024-28969
value: MEDIUM

Trust: 1.0

NVD: CVE-2024-28969
value: MEDIUM

Trust: 0.8

nvd@nist.gov: CVE-2024-28969
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 1.4
version: 3.1

Trust: 2.0

NVD: CVE-2024-28969
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2024-004984 // NVD: CVE-2024-28969 // NVD: CVE-2024-28969

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-284

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-004984 // NVD: CVE-2024-28969

EXTERNAL IDS

db:NVDid:CVE-2024-28969

Trust: 2.6

db:JVNDBid:JVNDB-2024-004984

Trust: 0.8

sources: JVNDB: JVNDB-2024-004984 // NVD: CVE-2024-28969

REFERENCES

url:https://www.dell.com/support/kbdoc/en-us/000225910/dsa-2024-181-security-update-for-dell-secure-connect-gateway-application-and-appliance-vulnerabilities

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2024-28969

Trust: 0.8

sources: JVNDB: JVNDB-2024-004984 // NVD: CVE-2024-28969

SOURCES

db:JVNDBid:JVNDB-2024-004984
db:NVDid:CVE-2024-28969

LAST UPDATE DATE

2024-08-15T12:49:55.366000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2024-004984date:2024-08-08T00:51:00
db:NVDid:CVE-2024-28969date:2024-08-06T15:28:06.497

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2024-004984date:2024-08-08T00:00:00
db:NVDid:CVE-2024-28969date:2024-06-13T15:15:52.183