First published: Wed Jan 11 2023(Updated: )
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Policy Manager for Secure Connect Gateway | >=5.10.00.00<5.14.00.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34441 is classified as a high severity vulnerability due to the potential for unauthorized admin access.
To mitigate CVE-2022-34441, upgrade the Dell EMC SCG Policy Manager to version 5.14 or later.
CVE-2022-34441 is caused by a hard-coded cryptographic key within the affected software versions.
CVE-2022-34441 affects versions 5.10 to 5.12 of the Dell EMC SCG Policy Manager.
Any user or entity using the affected versions of Dell EMC SCG Policy Manager is at risk of exploitation if they do not upgrade.