Vulnerability Details CVE-2025-36592
Dell Secure Connect Gateway (SCG) Policy Manager, version(s) 5.20. 5.22, 5.24, 5.26, 5.28, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.2%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2025-36592
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.00.05.11
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.10.00.00
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.10.00.10
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.12.00.00
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.12.00.10
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.14.00.00
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.14.00.10
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.14.00.14
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.16.00.14
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.18.00.20
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.20.00.10
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.22.00.16
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.22.00.18
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.24.00.14
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.26.00.18
-
cpe:2.3:a:dell:policy_manager_for_secure_connect_gateway:5.28.00.14