CVE-2026-73589

6.3

Dell · Secure Connect Gateway (SCG) Policy Manager

Dell Secure Connect Gateway (SCG) Policy Manager contains a weak password encoding vulnerability that allows local attackers to bypass security mechanisms and access sensitive information.

Executive summary

A weak password encoding vulnerability in Dell Secure Connect Gateway (SCG) Policy Manager allows local, low privileged attackers to gain unauthorized access and compromise system integrity.

Vulnerability

This vulnerability involves the use of weak encoding for passwords (CWE-261), which allows a local attacker with low privileges to bypass protection mechanisms, disclose sensitive information, and perform unauthorized tampering.

Business impact

Successful exploitation of this flaw could lead to unauthorized access to the Secure Connect Gateway, potentially exposing sensitive management credentials or configuration data. While the CVSS score of 6.3 reflects a medium severity due to the requirement for local access and high attack complexity, the potential for total technical impact means that organizations relying on SCG for infrastructure management face significant risks regarding unauthorized administrative control.

Remediation

Immediate Action: Update the Dell Secure Connect Gateway (SCG) Policy Manager to version 5.36.00.16 or later immediately.

Proactive Monitoring: Audit system access logs for suspicious local login patterns or unauthorized attempts to access configuration files associated with the policy manager.

Compensating Controls: Ensure that access to the underlying host operating system is strictly restricted to authorized administrators and implement robust disk encryption to mitigate risks from local access.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Although the exploitation requirements are restrictive, the ability to manipulate authentication credentials poses a severe risk to the security of the management environment. Administrators must prioritize applying the vendor provided update to version 5.36.00.16 to remediate this vulnerability and maintain the integrity of their Dell infrastructure management systems.

More Dell CVEs all →

History

  1. Analyst report written

Sources