Dell Secure Connect Gateway 5.20 contains an improper authentication vulnerability during the SRS to SCG update path. A remote low privileged attacker could potentially exploit this vulnerability, leading to impersonation of the server through presenting a fake self-signed certificate and communicating with the remote server.
References
Configurations
History
04 Dec 2024, 17:57
Type | Values Removed | Values Added |
---|---|---|
First Time |
Dell secure Connect Gateway
Dell |
|
References | () https://www.dell.com/support/kbdoc/en-us/000222433/dsa-2024-076-security-update-for-dell-secure-connect-gateway-appliance-vulnerabilities - Patch, Vendor Advisory | |
CPE | cpe:2.3:a:dell:secure_connect_gateway:5.20.00.10:*:*:*:*:*:*:* |
21 Nov 2024, 08:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.dell.com/support/kbdoc/en-us/000222433/dsa-2024-076-security-update-for-dell-secure-connect-gateway-appliance-vulnerabilities - |
01 Mar 2024, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-01 11:15
Updated : 2024-12-04 17:57
NVD link : CVE-2024-22457
Mitre link : CVE-2024-22457
CVE.ORG link : CVE-2024-22457
JSON object : View
Products Affected
dell
- secure_connect_gateway
CWE
CWE-290
Authentication Bypass by Spoofing