CVE-2024-37131

SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious actions on the application in the context of the authenticated user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:*:*:*:*:*:*:*:*

History

04 Feb 2025, 17:18

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000225956/dsa-2024-254-security-update-for-dell-secure-connect-gateway-policy-manager-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000225956/dsa-2024-254-security-update-for-dell-secure-connect-gateway-policy-manager-vulnerabilities - Vendor Advisory
CWE CWE-697
CPE cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:*:*:*:*:*:*:*:*
First Time Dell policy Manager For Secure Connect Gateway
Dell

21 Nov 2024, 09:23

Type Values Removed Values Added
Summary
  • (es) SCG Policy Manager, todas las versiones, contiene una vulnerabilidad de política de recursos de origen cruzado (CORP) demasiado permisiva. Un atacante remoto no autenticado podría explotar esta vulnerabilidad, lo que llevaría a la ejecución de acciones maliciosas en la aplicación en el contexto del usuario autenticado.
References () https://www.dell.com/support/kbdoc/en-us/000225956/dsa-2024-254-security-update-for-dell-secure-connect-gateway-policy-manager-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000225956/dsa-2024-254-security-update-for-dell-secure-connect-gateway-policy-manager-vulnerabilities -

13 Jun 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-13 15:15

Updated : 2025-02-04 17:18


NVD link : CVE-2024-37131

Mitre link : CVE-2024-37131

CVE.ORG link : CVE-2024-37131


JSON object : View

Products Affected

dell

  • policy_manager_for_secure_connect_gateway
CWE
CWE-942

Permissive Cross-domain Policy with Untrusted Domains

CWE-697

Incorrect Comparison