CVE-2025-36592
⚪ Do wiadomości
Luka XSS w Dell Secure Connect Gateway umożliwia zdalne wstrzyknięcie skryptu przez atakującego.
CVSS
5.4
EPSS
0.2%
Exploit
none
Vendor
dell
Opis źródłowy (NVD)
Dell Secure Connect Gateway (SCG) Policy Manager, version(s) 5.20. 5.22, 5.24, 5.26, 5.28, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.4 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2025-10-30 16:15:35 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 22:10:00 UTC |