CVE-2024-37131: Dell Policy Manager For Secure Connect Gateway

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious actions on the application in the context of the authenticated user.

Affected products

  • Dell Policy Manager For Secure Connect Gateway: from 5.18.00.20, before 5.24.00.14 (fixed in 5.24.00.14)

Published 2024-06-13. Last modified 2026-06-17.