Podatność CVE-2024-22457


Publikacja: 2024-03-01

Opis:
Dell Secure Connect Gateway 5.20 contains an improper authentication vulnerability during the SRS to SCG update path. A remote low privileged attacker could potentially exploit this vulnerability, leading to impersonation of the server through presenting a fake self-signed certificate and communicating with the remote server.

Typ:

CWE-290

(Authentication Bypass by Spoofing)

 Referencje:
https://www.dell.com/support/kbdoc/en-us/000222433/dsa-2024-076-security-update-for-dell-secure-connect-gateway-appliance-vulnerabilities

Copyright 2024, cxsecurity.com

 

Back to Top