9.8
CVE-2024-37131
- EPSS 4.41%
- Veröffentlicht 13.06.2024 15:15:52
- Zuletzt bearbeitet 20.05.2025 18:56:59
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious actions on the application in the context of the authenticated user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Policy Manager For Secure Connect Gateway Version >= 5.18.00.20 < 5.24.00.14
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.41% | 0.885 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| security_alert@emc.com | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-942 Permissive Cross-domain Policy with Untrusted Domains
The product uses a cross-domain policy file that includes domains that should not be trusted.