Show filters
125 Total Results
Displaying 11-20 of 125
Sort by:
Attacker Value
Unknown
CVE-2024-45504
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated attacker to hijack the authentication of the user and to perform unintended operations if the user views a malicious page while logged in.
0
Attacker Value
Unknown
CVE-2024-6398
Disclosure Date: July 15, 2024 (last updated February 26, 2025)
An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a customizable block page to be disclosed to third-party websites due to Same Origin Policy Bypass of browsers in certain scenarios. The risk is low, because other recommended default security policies such as URL categorization and GTI are in place in most policies to block access to uncategorized/high risk websites. Any information disclosed depends on how the customers have customized the block pages.
0
Attacker Value
Unknown
CVE-2024-6744
Disclosure Date: July 15, 2024 (last updated February 26, 2025)
The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the remote server.
0
Attacker Value
Unknown
CVE-2024-29169
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing potential unauthorized access and modification of application data.
0
Attacker Value
Unknown
CVE-2024-37131
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious actions on the application in the context of the authenticated user.
0
Attacker Value
Unknown
CVE-2024-29168
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing potential unauthorized access and modification of application data.
0
Attacker Value
Unknown
CVE-2024-28969
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources.
0
Attacker Value
Unknown
CVE-2024-28968
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for internal email and collection settings REST APIs (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state.
0
Attacker Value
Unknown
CVE-2024-28967
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state.
0
Attacker Value
Unknown
CVE-2024-28966
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state.
0