PT-2022-6358 · Dell Emc · Dell Emc Scg Policy Manager
Mal
+1
·
Published
2022-11-10
·
Updated
2023-01-25
·
CVE-2022-34442
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell EMC SCG Policy Manager versions 5.10 through 5.12
Description
The issue is related to the use of a hard-coded cryptographic key in the Policy Manager software of Dell Secure Connect Gateway (SCG). An attacker with knowledge of the hard-coded sensitive information could potentially exploit this to login to the system and gain LDAP user privileges.
Recommendations
For versions 5.10 through 5.12, consider disabling access to sensitive areas of the system until a patch is available to prevent potential privilege escalation.
As a temporary workaround, restrict access to the system to minimize the risk of exploitation until the issue is resolved.
Avoid using the system for sensitive operations until the hard-coded cryptographic key vulnerability is fixed.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Emc Scg Policy Manager