CVE-2026-73586
6.4Dell · Secure Connect Gateway (SCG) Policy Manager
Dell Secure Connect Gateway (SCG) Policy Manager contains an insufficient session expiration vulnerability, allowing low privileged attackers to bypass security mechanisms.
Executive summary
An insufficient session expiration vulnerability in Dell Secure Connect Gateway (SCG) Policy Manager could allow a low privileged, network-adjacent attacker to escalate privileges and gain unauthorized access.
Vulnerability
The application fails to properly expire user sessions, which creates a window of opportunity for an attacker. This flaw requires the attacker to have adjacent network access and low-level privileges to successfully execute a privilege escalation or protection mechanism bypass.
Business impact
Successful exploitation of this vulnerability could lead to significant unauthorized access to the Policy Manager, potentially compromising the integrity and confidentiality of sensitive gateway configurations. While the CVSS score of 6.4 classifies this as a Medium severity issue, the risk of privilege escalation within a gateway management component necessitates prompt attention to prevent lateral movement or administrative takeover.
Remediation
Immediate Action: Update Dell Secure Connect Gateway (SCG) Policy Manager to version 5.36.00.16 or later as specified by the vendor security advisory.
Proactive Monitoring: Audit application access logs for irregular session patterns or unauthorized administrative actions occurring outside of expected maintenance windows.
Compensating Controls: Ensure the management interface is restricted to trusted network segments and implement strict network access control lists to limit the potential for adjacent network attacks.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Security teams should prioritize updating the affected Dell Secure Connect Gateway instances during the next scheduled maintenance cycle. Given the potential for privilege escalation, verifying that the patch is applied across all deployed gateways is essential to maintaining a secure management environment.
More Dell CVEs all →
History
- Analyst report written