← All Advisories

CVE-2024-38487

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2024-38487

Key Details

CVECVE-2024-38487
CVSS Score / Version7.0 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is low; user interaction is none; scope is changed; confidentiality impact is low; integrity impact is low; availability impact is high.
Affected productsdell EMC VxRail Appliance
Classified asCWE-269 (Improper Privilege Management)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
dellEMC VxRail Appliance
SubsystemsGeneral OT
SectorsMultiple

What to Know

api-gateway container running with root privilege would allow an attacker to escape the container and access host system to perform unintended actions.

What to Do

Monitor dell's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2024-38487
CVEhttps://www.cve.org/CVERecord?id=CVE-2024-38487