Impact
This vulnerability is a Download of Code Without Integrity Check flaw that allows an unauthenticated attacker with remote access to download and execute arbitrary code. The flaw can be leveraged to execute code on the device, expose sensitive information, alter configurations or data, and bypass existing protection mechanisms. The impact is significant because it enables full control over the affected system without authentication.
Affected Systems
The flaw affects Dell Secure Connect Gateway (SCG) Policy Manager installations prior to version 5.34.00.16 and prior to 5.36. Any appliance running these versions is at risk if exposed to external networks.
Risk and Exploitability
The CVSS score of 4.7 indicates a moderate severity. EPSS data is currently unavailable, but the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can exploit the flaw remotely, typically by interacting with the SCG Policy Manager’s exposed services. The lack of authentication, coupled with remote reachability, increases the likelihood that the vulnerability could be used to compromise systems.
OpenCVE Enrichment