Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000219035


DSA-2023-398: Security Update for Dell Secure Connect Gateway Security Policy Manager Vulnerabilities

Summary: Dell Secure Connect Gateway Policy Manager remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

Third-party Component CVEs More Information
SUSE Enterprise 12 SP5 CVE-2023-3446
 
See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
 
Apache Tomcat CVE-2023-41080
 
See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

 
PostgreSQL CVE-2023-39417, CVE-2023-39418
 
See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

 
Azul Systems JRE 17 CVE-2023-22006, CVE-2023-22036, CVE-2023-22041, CVE-2023-22044, CVE-2023-22045, CVE-2023-22049,  See NVD link below for individual scores for each CVE.
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2023-3446, CVE-2023-39417, CVE-2023-39418, CVE-2023-22006, CVE-2023-22036, CVE-2023-22041, CVE-2023-22044, CVE-2023-22045, CVE-2023-22049, CVE-2023-41080 SCG Policy Manager Version
5.18.00.20
Version 5.20 Support for Secure Connect Gateway - Virtual Edition | Drivers & Downloads | Dell US
CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2023-3446, CVE-2023-39417, CVE-2023-39418, CVE-2023-22006, CVE-2023-22036, CVE-2023-22041, CVE-2023-22044, CVE-2023-22045, CVE-2023-22049, CVE-2023-41080 SCG Policy Manager Version
5.18.00.20
Version 5.20 Support for Secure Connect Gateway - Virtual Edition | Drivers & Downloads | Dell US

Workarounds and Mitigations

None

Revision History

RevisionDateDescription
1.02023-11-08Initial Release
2.02023-11-13Updates for enhanced presentation with no changes to content.

Related Information


Article Properties


Affected Product

Secure Connect Gateway, Secure Connect Gateway

Last Published Date

13 Nov 2023

Version

4

Article Type

Dell Security Advisory