CVE-2025-46363: Path Traversal
Dell Secure Connect Gateway (SCG) 5.0 Application and Appliance version(s) 5.26.00.00 - 5.30.00.00, contain a Relative Path Traversal vulnerability in the SCG exposed for an internal collection download REST API (if this REST API is enabled by Admin user from UI). A low privileged attacker with remote access could potentially exploit this vulnerability, leading to allowing relative path traversal to restricted resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46363?
CVE-2025-46363 is classified as a low severity vulnerability.
How do I fix CVE-2025-46363?
To mitigate CVE-2025-46363, it is recommended to disable the affected REST API if it is not in use or update to a patched version of Dell Secure Connect Gateway.
What versions of Dell Secure Connect Gateway are affected by CVE-2025-46363?
CVE-2025-46363 affects Dell Secure Connect Gateway versions 5.26.00.00 through 5.30.00.00.
What type of vulnerability is CVE-2025-46363?
CVE-2025-46363 is a Relative Path Traversal vulnerability.
Can a remote attacker exploit CVE-2025-46363?
Yes, a low privileged remote attacker can exploit CVE-2025-46363 if the vulnerable REST API is enabled.