CVE-2024-37131

SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious actions on the application in the context of the authenticated user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:*:*:*:*:*:*:*:*

History

20 May 2025, 18:56

Type Values Removed Values Added
CWE CWE-697

04 Feb 2025, 17:18

Type Values Removed Values Added
CPE cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000225956/dsa-2024-254-security-update-for-dell-secure-connect-gateway-policy-manager-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000225956/dsa-2024-254-security-update-for-dell-secure-connect-gateway-policy-manager-vulnerabilities - Vendor Advisory
CWE CWE-697
First Time Dell
Dell policy Manager For Secure Connect Gateway

21 Nov 2024, 09:23

Type Values Removed Values Added
Summary
  • (es) SCG Policy Manager, todas las versiones, contiene una vulnerabilidad de política de recursos de origen cruzado (CORP) demasiado permisiva. Un atacante remoto no autenticado podría explotar esta vulnerabilidad, lo que llevaría a la ejecución de acciones maliciosas en la aplicación en el contexto del usuario autenticado.
References () https://www.dell.com/support/kbdoc/en-us/000225956/dsa-2024-254-security-update-for-dell-secure-connect-gateway-policy-manager-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000225956/dsa-2024-254-security-update-for-dell-secure-connect-gateway-policy-manager-vulnerabilities -

13 Jun 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-13 15:15

Updated : 2025-05-20 18:56


NVD link : CVE-2024-37131

Mitre link : CVE-2024-37131

CVE.ORG link : CVE-2024-37131


JSON object : View

Products Affected

dell

  • policy_manager_for_secure_connect_gateway
CWE
CWE-942

Permissive Cross-domain Policy with Untrusted Domains