Impact
Dell Secure Connect Gateway (SCG) Policy Manager suffers from an Improper Privilege Management flaw that can be triggered by a low‑privileged attacker who has remote access to the device. The deficiency in privilege checks can allow the attacker to gain unauthorized access to administrative functions, thereby potentially enabling the modification of security policies, viewing of confidential configuration data, or disruption of service availability. The vulnerability arises from insufficient enforcement of privilege levels, exposing the system to unauthorized manipulation of its configuration and operation.
Affected Systems
Dell Secure Connect Gateway (SCG) Policy Manager deployments running versions earlier than 5.34.00.16. The flaw exists across all releases that predate the stated version and affects the product’s default configuration for remote management interfaces.
Risk and Exploitability
The flaw carries a CVSS base score of 6.8, indicating moderate impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests no widespread exploitation to date. Based on the description, the likely attack vector is remote exploitation via the device’s management interface that can be accessed by operators with low privilege, such as guest or limited‑role accounts. An attacker would need remote connectivity to the device, though no specific network prerequisites are noted beyond general remote access.
OpenCVE Enrichment