Impact
The vulnerability is an initialization of a resource with an insecure default in Dell Secure Connect Gateway Policy Manager. Because of this flaw, a high privileged attacker who has local access can trigger a denial of service, disclose confidential information, and bypass protection mechanisms. The weakness corresponds to CWE-1188, which highlights failure to set secure defaults during resource initialization.
Affected Systems
Affected systems are Dell Secure Connect Gateway Policy Managers running any version earlier than 5.34.00.16. The vulnerability is present in all such installations regardless of configuration, providing a broad attack surface to local privileged users.
Risk and Exploitability
The CVSS score of 5.2 indicates moderate severity, and the EPSS score is currently unavailable, making it unclear how often this flaw is actively exploited. Because exploitation requires high privileged local access, the attack surface is limited to administrators or technicians with physical or remote privileged rights. As the vulnerability is not listed in the CISA KEV catalog, no known exploit code is publicly documented at this time.
OpenCVE Enrichment