DSA-2022-273: Dell Secure Connect Gateway (SCG) Policy Manager Security Update for Multiple Proprietary Code Vulnerabilities

요약: Dell Secure Connect Gateway (SCG) Policy Manager contains remediation for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

영향

Critical

세부 정보

Proprietary Code CVEs   Description   CVSS Base Score   CVSS Vector String   
CVE-2022-34440 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges. 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2022-34441
 
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges. 8.0 HIGH
 
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVE-2022-34442 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges. 8.0 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVE-2022-34462 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges. 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 
Third-Party Component
 
CVEs More information
SUSE Enterprise 12 SP5 CVE-2022-1292 
 
See NVD (http://nvd.nist.gov/) for individual scores for each CVE
 
SUSE Enterprise 12 SP5 CVE-2022-2068
 
org.yaml.snakeyaml CVE-2022-38752
 
com.fasterxml.jackson CVE-2022-42003
 
CVE-2022-42004
 
Proprietary Code CVEs   Description   CVSS Base Score   CVSS Vector String   
CVE-2022-34440 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges. 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2022-34441
 
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges. 8.0 HIGH
 
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVE-2022-34442 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges. 8.0 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVE-2022-34462 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges. 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 
Third-Party Component
 
CVEs More information
SUSE Enterprise 12 SP5 CVE-2022-1292 
 
See NVD (http://nvd.nist.gov/) for individual scores for each CVE
 
SUSE Enterprise 12 SP5 CVE-2022-2068
 
org.yaml.snakeyaml CVE-2022-38752
 
com.fasterxml.jackson CVE-2022-42003
 
CVE-2022-42004
 
Dell Technologies는 모든 고객이 CVSS 기본 점수와 관련 임시 및 환경 점수를 모두 고려할 것을 권장합니다. 이 경우 특정 보안 취약성과 관련된 잠재적인 심각도에 영향을 미칠 수 있습니다.

영향을 받는 제품 및 문제 해결

CVEs Addressed Product Affected Version Updated Version Link to Update
CVE-2022-1292  Dell SCG Policy Manager 5.12.00.00 5.14.00.00 Support for Secure Connect Gateway - Virtual Edition | Drivers & Downloads | Dell US
CVE-2022-2068
CVE-2022-34440
CVE-2022-34441
CVE-2022-34442
CVE-2022-34462
CVE-2022-42003
CVE-2022-42004
CVEs Addressed Product Affected Version Updated Version Link to Update
CVE-2022-1292  Dell SCG Policy Manager 5.12.00.00 5.14.00.00 Support for Secure Connect Gateway - Virtual Edition | Drivers & Downloads | Dell US
CVE-2022-2068
CVE-2022-34440
CVE-2022-34441
CVE-2022-34442
CVE-2022-34462
CVE-2022-42003
CVE-2022-42004

개정 내역

RevisionDateDescription
1.02022-11-10Initial Release
2.02024-04-30Updated Affected Products and Remediation table: Updated link 

감사의 말

Dell would like to thank Matei "Mal" Badanoiu and sradulea for reporting CVE-2022-34440, CVE-2022-34441, CVE-2022-34442 and CVE-2022-34462.
 

관련 정보

해당 제품

Secure Connect Gateway
문서 속성
문서 번호: 000204995
문서 유형: Dell Security Advisory
마지막 수정 시간: 19 9월 2025
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.