Sensitive Information Disclosure in Dell EMC Secure Connect Gateway
CVE-2021-36340

7.8HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
20 November 2021

Summary

The Dell EMC Secure Connect Gateway versions 5.00.00.10 and earlier are susceptible to a vulnerability that allows a local malicious user to access and read sensitive information. This security flaw poses a risk, potentially enabling unauthorized access to sensitive data, which could be abused by an attacker. It is crucial for users to be aware of this vulnerability and apply necessary updates to mitigate potential threats.

Affected Version(s)

Secure Connect Gateway (SCG) 5.0 Application < 5.00.05.10

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.