CORP Vulnerability in SCG Policy Manager Allows Remote Execution of Malicious Actions

CVE-2024-37131
7.5HIGH

Key Information

Vendor
Dell
Status
Secure Connect Gateway (scg) Policy Manager
Vendor
CVE Published:
13 June 2024

Summary

SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious actions on the application in the context of the authenticated user.

Affected Version(s)

Secure Connect Gateway (SCG) Policy Manager <= 5.22.00.18

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.