Impact
The vulnerability is an Incorrect Permission Assignment for a critical resource in Dell Secure Connect Gateway Policy Manager. A low privileged attacker who already has local access can exploit the improper permissions to obtain higher privileges, potentially controlling the gateway or accessing sensitive configuration data. The weakness is classified as CWE-732.
Affected Systems
Dell Secure Connect Gateway Policy Manager versions prior to 5.34.00.16 are impacted. The issue resides in the Policy Manager component used by Dell SCG deployments.
Risk and Exploitability
The CVSS score of 7.8 indicates a medium–high severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting that public exploitation is not widely documented. The exploit requires local access with a low privileged account, so an attacker would need physical or administrative access to the device before escalating privileges. Once the incorrect permissions are leveraged, the attacker could gain full control over the SCG system, leading to further compromise of the network.
OpenCVE Enrichment