CVE-2024-37131

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/06/2024
Last modified:
20/05/2025

Description

SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious actions on the application in the context of the authenticated user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:*:*:*:*:*:*:*:* 5.18.00.20 (including) 5.24.00.14 (excluding)