#VU96275 Improper access control in Dell Secure Connect Gateway - CVE-2024-28965
Published: August 21, 2024
Dell Secure Connect Gateway
Dell
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to SCG exposed for an internal enable REST API (if enabled by Admin user from UI). A remote user can execute certain Internal APIs applicable only for Admin Users on the application's backend database that could potentially allow access to restricted resources and change of state.