Impact
Dell Secure Connect Gateway (SCG) Policy Manager contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability that enables a low‑privileged attacker with remote access to elevate privileges, gain filesystem access, and execute code on the host. The weakness, classified as CWE‑829, permits the attacker to activate internal functions that were not intended to be exposed to untrusted inputs, effectively turning the system into a conduit for malicious actions.
Affected Systems
Affected by this vulnerability are all Dell Secure Connect Gateway Policy Manager installations running versions older than 5.34.00.16. The issue does not affect newer releases, so upgrading to a version that includes the Dell security update is required to resolve the problem.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, though the EPSS score is not available, implying limited data on current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need remote network connectivity to the SCG and only low privileged credentials, so the risk is elevated for systems exposed to untrusted networks. The potential for remote execution makes this a critical threat if not remediated promptly.
OpenCVE Enrichment