CVE-2023-39252 MEDIUM

CVE-2023-39252

Vendor Dell
Product Secure Connect Gateway (SCG) Policy Manager
Weakness CWE-327 · Broken crypto
Published September 21, 2023
Last update September 24, 2024

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Dell SCG Policy Manager 5.16.00.14 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information.

Key dates

02Disclosure timeline

September 21, 2023 CVE published
September 24, 2024 Record updated