Impact
This vulnerability arises from a Use of Less Trusted Source condition that allows an unauthenticated attacker with remote access to potentially alter configuration information within the Dell Secure Connect Gateway Policy Manager. The impact is limited to information tampering—data integrity could be compromised if an attacker modifies policy settings. No denial of service or code execution is indicated by the current description.
Affected Systems
Affected are Dell Secure Connect Gateway Policy Manager installations running any version prior to 5.34.00.16. The product is delivered by Dell under the Secure Connect Gateway umbrella and deployed by organizations that require secure remote access gateways.
Risk and Exploitability
The CVSS score of 3.7 reflects a moderate severity, primarily due to lack of authentication and limited impact. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting low exploitation likelihood. Attackers would need remote network-level access to the SCG or a path to reach the Policy Manager exposed over the internet or an internal network. In the absence of authentication, a determined attacker could manipulate policies once they reach the vulnerable component, but the overall risk is considered limited compared to higher severity exploits.
OpenCVE Enrichment