Impact
A missing authorization flaw in the Dell Secure Connect Gateway Policy Manager allows an attacker with low privileges who can reach the system remotely to gain higher level privileges. This vulnerability permits the attacker to manipulate configuration or data that should only be accessible by authorized users. The lack of proper checks on actions within the Policy Manager means an attacker can execute privileged commands without needing administrative credentials.
Affected Systems
Dell Secure Connect Gateway Policy Manager, any version earlier than 5.34.00.16. Users running these older builds are exposed to the missing authorization issue. The vulnerability applies to all deployments of the policy manager component that have remote access enabled.
Risk and Exploitability
The CVSS score of 4.3 indicates the weakness poses a medium risk overall. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation is not documented. Nevertheless, the attack vector is inferred to be remote access to the Policy Manager interface by an attacker with limited credentials; once accessed, privilege escalation can occur. Given the relatively low severity score but potential for significant impact if exploited, the risk remains moderate and warrants timely remediation.
OpenCVE Enrichment