Incorrect Default Permissions Vulnerability in Dell Secure Connect Gateway (SCG) 5.24

CVE-2024-47240

6.3MEDIUM

Key Information

Vendor
Dell
Status
Secure Connect Gateway (scg) 5.0 Appliance - Srs
Vendor
CVE Published:
18 October 2024

Summary

Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A local attacker with low privileges can access the file system and could potentially exploit this vulnerability to gain write access to unauthorized data and cause a version update failure condition.

Affected Version(s)

Secure Connect Gateway (SCG) 5.0 Appliance - SRS = 5.24.00.14

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.