Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-24903

Опубликовано: 01 мар. 2024
Источник: nvd
CVSS3: 8
EPSS Низкий

Описание

Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:*:*:*:*:*:*:*:*
Версия от 5.10.00.10 (включая) до 5.22.00.16 (исключая)

EPSS

Процентиль: 24%
0.00082
Низкий

8 High

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 8
github
почти 2 года назад

Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change.

EPSS

Процентиль: 24%
0.00082
Низкий

8 High

CVSS3

Дефекты

CWE-640