Status: UPDATED
| Advisory ID: CVE-2024-38487
Key Details
| CVE | CVE-2024-38487 |
| CVSS Score / Version | 7.0 (High) / CVSS v3.1 |
| Updated | 2026-10-02 |
| CVSS Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H |
| CVSS Prose | attack vector is local; attack complexity is high; privileges required is low; user interaction is none; scope is changed; confidentiality impact is low; integrity impact is low; availability impact is high. |
| Affected products | dell EMC VxRail Appliance |
| Classified as | CWE-269 (Improper Privilege Management) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
api-gateway container running with root privilege would allow an attacker to escape the container and access host system to perform unintended actions.
What to Do
Monitor dell's web page for any future patch releases.
References