Vulnerability identifier: #VU102826
Vulnerability risk: Medium
CVSSv4.0: 6.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-47241
CWE-ID:
CWE-295
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Dell Secure Connect Gateway
Server applications /
Other server solutions
Vendor: Dell
Description
The vulnerability allows a remote attacker to gain unauthorized access and modify transmitted data.
The vulnerability exists due to excessive data output by the application. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access and modification of transmitted data.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Dell Secure Connect Gateway: before 5.26.00.18
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.