Impact
Dell Secure Connect Gateway (SCG) Policy Manager versions older than 5.34.00.16 contain an inclusion of sensitive information in source code that an unauthenticated remote attacker could exploit, resulting in exposure of confidential data. The vulnerability is classified as CWE-540 and carries a CVSS score of 7.5, describing a moderate to high severity risk to confidentiality.
Affected Systems
The affected product is Dell Secure Connect Gateway Policy Manager provided by Dell. Versions prior to 5.34.00.16 are vulnerable; any installation running those releases may be compromised if exposed to remote access.
Risk and Exploitability
The absence of an EPSS score limits precise exploitation probability, but the lack of authentication requirement means any remote user could potentially read the exposed data. The vulnerability is not listed in the CISA KEV catalog, yet the high CVSS indicates a substantial risk. Enterprise administrators should treat the exposure as a serious confidentiality breach and prioritize remediation.
OpenCVE Enrichment