Impact
A flaw in Dell Secure Connect Gateway Policy Manager allows an unauthenticated remote attacker to trigger error messages that include sensitive information, exposing confidential data. The vulnerability does not permit code execution or privilege escalation but can be used to gather information from the system. This information exposure could include internal configuration details and user data that are normally protected.
Affected Systems
The vulnerability affects Dell Secure Connect Gateway Policy Manager versions earlier than 5.34.00.16. It is specific to the Dell SCG Policy Manager component and applies to all deployments using those legacy versions.
Risk and Exploitability
The CVSS score of 3.7 indicates a moderate impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that it is unverified in terms of active exploitation. The attack requires unauthenticated remote access to the SCG system; no additional credentials are required, but the attacker must be able to reach the device over the network.
OpenCVE Enrichment