Vulnerability Description
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Policy Manager For Secure Connect Gateway | < 5.22.00.16 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/en-us/000222330/dsa-2024-077-security-update-PatchVendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000222330/dsa-2024-077-security-update-PatchVendor Advisory
FAQ
What is CVE-2024-24904?
CVE-2024-24904 is a vulnerability with a CVSS score of 7.6 (HIGH). Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability. An adjacent network high privileged attacker could potentially exploit this vuln...
How severe is CVE-2024-24904?
CVE-2024-24904 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-24904?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Policy Manager For Secure Connect Gateway.