Impact
The vulnerability is an Improper Restriction of Rendered UI Layers or Frames flaw in Dell Secure Connect Gateway Policy Manager. Remote attackers with low privileged access can manipulate the rendering environment, which may allow them to elevate privileges and potentially steal user sessions. The flaw exists because the appliance does not enforce proper boundaries between UI layers or frames.
Affected Systems
Dell Secure Connect Gateway (SCG) Policy Manager versions earlier than 5.34.00.16 are affected. The issue resides in the Policy Manager component of the appliance.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity. EPSS data is not available, and the vulnerability is not listed in DSA KEV, suggesting no known exploit at present. An attacker must first obtain low‑privileged remote access to the device before the flaw can be leveraged, which raises the practical risk to moderate levels compared to higher‑privilege exploits.
OpenCVE Enrichment