SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious actions on the application in the context of the authenticated user.
References
Configurations
History
20 May 2025, 18:56
Type | Values Removed | Values Added |
---|---|---|
CWE |
04 Feb 2025, 17:18
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:*:*:*:*:*:*:*:* | |
References | () https://www.dell.com/support/kbdoc/en-us/000225956/dsa-2024-254-security-update-for-dell-secure-connect-gateway-policy-manager-vulnerabilities - Vendor Advisory | |
CWE | CWE-697 | |
First Time |
Dell
Dell policy Manager For Secure Connect Gateway |
21 Nov 2024, 09:23
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://www.dell.com/support/kbdoc/en-us/000225956/dsa-2024-254-security-update-for-dell-secure-connect-gateway-policy-manager-vulnerabilities - |
13 Jun 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-13 15:15
Updated : 2025-05-20 18:56
NVD link : CVE-2024-37131
Mitre link : CVE-2024-37131
CVE.ORG link : CVE-2024-37131
JSON object : View
Products Affected
dell
- policy_manager_for_secure_connect_gateway
CWE
CWE-942
Permissive Cross-domain Policy with Untrusted Domains