CVE-2023-44293
Last modified
CVE-2023-44293 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the product database. . EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the product database.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Secure Connect Gateway | >= 5.10.00.00, < 5.20.00.00 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-44293?
How severe is CVE-2023-44293?
How do I fix CVE-2023-44293?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-44288 Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an…7.5
- CVE-2023-44289 Dell Command | Configure versions prior to 4.11.0, contain …7.8
- CVE-2023-4429Use after free in Loader in Google Chrome prior to 116.0.584…8.8
- CVE-2023-44290 Dell Command | Monitor versions prior to 10.10.0, contain a…7.8
- CVE-2023-44291 Dell DM5500 5.14.0.0 contains an OS command injection vul…7.2
- CVE-2023-44292 Dell Repository Manager, 3.4.3 and prior, contains an Impro…7.8
- CVE-2023-44294 In Dell Secure Connect Gateway Application and Secure Conne…6.5
- CVE-2023-44295 Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x cont…8.1
- CVE-2023-44296 Dell ELab-Navigator, version 3.1.9 contains a hard-coded cr…5.5
- CVE-2023-44297 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precisi…6.8
- CVE-2023-44298 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precisi…6.8
- CVE-2023-4430Use after free in Vulkan in Google Chrome prior to 116.0.584…8.8
Are you affected by CVE-2023-44293?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
