Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgh6-gfm4-cj58

Опубликовано: 01 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change.

Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change.

EPSS

Процентиль: 24%
0.00082
Низкий

8 High

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 8
nvd
почти 2 года назад

Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change.

EPSS

Процентиль: 24%
0.00082
Низкий

8 High

CVSS3

Дефекты

CWE-640