Impact
Dell Secure Connect Gateway Policy Manager before version 5.34.00.16 contains an improper restriction of excessive authentication attempts flaw (CWE-307). The vulnerability permits an unauthenticated attacker with remote access to bypass protection mechanisms, elevate privileges, and gain unauthorized access to the system.
Affected Systems
The flaw affects Dell Secure Connect Gateway Policy Manager products, specifically all versions earlier than 5.34.00.16.
Risk and Exploitability
The CVSS rating of 7.4 signals a high severity vulnerability, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the issue remotely without authentication, making the potential impact significant. The lack of EPSS data indicates uncertainty about current exploit prevalence, but the high CVSS suggests that if exploited, the attacker could gain elevated privileges and bypass protective controls.
OpenCVE Enrichment