Impact
The vulnerability in Dell Secure Connect Gateway (SCG) Policy Manager is an Initialization of a Resource with an Insecure Default, listed as CWE-1188. An attacker with high privileges and remote access can leverage this flaw to elevate privileges, tamper with information, bypass protection mechanisms, and gain unauthorized access. The impact can compromise the integrity and confidentiality of the system and enable further malicious actions by the compromised account.
Affected Systems
The affected product is Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16. All installations of these versions are vulnerable unless updated to the latest release.
Risk and Exploitability
The CVSS score of 3.8 indicates a low severity, and the EPSS score is not available, suggesting limited publicly known exploits. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires a high privileged attacker with remote access and is inferred from the description; the system must be accessed remotely to exploit the insecure initialization.
OpenCVE Enrichment