DSA-2022-273: Dell Secure Connect Gateway (SCG) Policy Manager Security Update for Multiple Proprietary Code Vulnerabilities

摘要: Dell Secure Connect Gateway (SCG) Policy Manager contains remediation for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.

本文章適用於 本文章不適用於 本文無關於任何特定產品。 本文未識別所有產品版本。

影響

Critical

詳細資料

Proprietary Code CVEs   Description   CVSS Base Score   CVSS Vector String   
CVE-2022-34440 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges. 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2022-34441
 
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges. 8.0 HIGH
 
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVE-2022-34442 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges. 8.0 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVE-2022-34462 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges. 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 
Third-Party Component
 
CVEs More information
SUSE Enterprise 12 SP5 CVE-2022-1292 
 
See NVD (http://nvd.nist.gov/) for individual scores for each CVE
 
SUSE Enterprise 12 SP5 CVE-2022-2068
 
org.yaml.snakeyaml CVE-2022-38752
 
com.fasterxml.jackson CVE-2022-42003
 
CVE-2022-42004
 
Proprietary Code CVEs   Description   CVSS Base Score   CVSS Vector String   
CVE-2022-34440 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges. 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2022-34441
 
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges. 8.0 HIGH
 
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVE-2022-34442 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges. 8.0 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVE-2022-34462 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges. 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 
Third-Party Component
 
CVEs More information
SUSE Enterprise 12 SP5 CVE-2022-1292 
 
See NVD (http://nvd.nist.gov/) for individual scores for each CVE
 
SUSE Enterprise 12 SP5 CVE-2022-2068
 
org.yaml.snakeyaml CVE-2022-38752
 
com.fasterxml.jackson CVE-2022-42003
 
CVE-2022-42004
 
Dell Technologies 建議所有客戶不僅要參考 CVSS 基本分數,也要將可能會影響與特定安全漏洞相關之潛在嚴重性的所有相關暫時和環境分數納入考量。

受影響的產品與補救措施

CVEs Addressed Product Affected Version Updated Version Link to Update
CVE-2022-1292  Dell SCG Policy Manager 5.12.00.00 5.14.00.00 Support for Secure Connect Gateway - Virtual Edition | Drivers & Downloads | Dell US
CVE-2022-2068
CVE-2022-34440
CVE-2022-34441
CVE-2022-34442
CVE-2022-34462
CVE-2022-42003
CVE-2022-42004
CVEs Addressed Product Affected Version Updated Version Link to Update
CVE-2022-1292  Dell SCG Policy Manager 5.12.00.00 5.14.00.00 Support for Secure Connect Gateway - Virtual Edition | Drivers & Downloads | Dell US
CVE-2022-2068
CVE-2022-34440
CVE-2022-34441
CVE-2022-34442
CVE-2022-34462
CVE-2022-42003
CVE-2022-42004

修訂歷史記錄

RevisionDateDescription
1.02022-11-10Initial Release
2.02024-04-30Updated Affected Products and Remediation table: Updated link 

感謝

Dell would like to thank Matei "Mal" Badanoiu and sradulea for reporting CVE-2022-34440, CVE-2022-34441, CVE-2022-34442 and CVE-2022-34462.
 

相關資訊

受影響的產品

Secure Connect Gateway
文章屬性
文章編號: 000204995
文章類型: Dell Security Advisory
上次修改時間: 19 9月 2025
向其他 Dell 使用者尋求您問題的答案
支援服務
檢查您的裝置是否在支援服務的涵蓋範圍內。