HomeDellCVE-2025-36592

CVE-2025-36592

MEDIUM
5.4CVSS
Published: 2025-10-30
Updated: 2025-11-10
AI Analysis

Description

Dell Secure Connect Gateway (SCG) Policy Manager, version(s) 5.20. 5.22, 5.24, 5.26, 5.28, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Script injection.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
required
Scope
unchanged
Confidentiality
low
Integrity
low
Availability
none
Weaknesses
CWE-79

Metadata

Primary Vendor
DELL
Published
10/30/2025
Last Modified
11/10/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

dell : policy_manager_for_secure_connect_gateway

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief