Vulnerability CVE-2024-22457


Published: 2024-03-01

Description:
Dell Secure Connect Gateway 5.20 contains an improper authentication vulnerability during the SRS to SCG update path. A remote low privileged attacker could potentially exploit this vulnerability, leading to impersonation of the server through presenting a fake self-signed certificate and communicating with the remote server.

Type:

CWE-290

(Authentication Bypass by Spoofing)

 References:
https://www.dell.com/support/kbdoc/en-us/000222433/dsa-2024-076-security-update-for-dell-secure-connect-gateway-appliance-vulnerabilities

Copyright 2024, cxsecurity.com

 

Back to Top