CVE-2024-24905

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Mar 1, 2024
CWE ID 79

Summary

CVE-2024-24905 is a vulnerability found in Dell Secure Connect Gateway (SCG) Policy Manager, affecting all versions. The vulnerability allows a high privileged attacker on an adjacent network to exploit it, resulting in the storage of malicious HTML or JavaScript code in a trusted application data store. When a user accesses the data store through their browser, the malicious code executes within the context of the vulnerable web application. This could lead to information disclosure, session theft, or client-side request forgery. The vulnerability has a base severity rating of HIGH and requires high privileges and user interaction for exploitation. The CWE classification for this vulnerability is CWE-79 (Improper Neutralization of Input During Web Page Generation - Cross-site Scripting).

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-24905 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options