CVE-2026-73589: Medium severity Dell Secure Connect Gateway (SCG) Policy Manager vulnerability
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection mechanism bypass, and Unauthorized access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Secure Connect Gateway (SCG) Policy Managerto a version that resolves this vulnerability.Fixed in 5.34.00.16 - Upgrade
Upgrade
Dell Secure Connect Gateway (SCG) Policy Managerto a version that resolves this vulnerability.Fixed in 5.36
Event History
Frequently Asked Questions
Who is realistically exposed to this vulnerability?
Systems running Dell Secure Connect Gateway Policy Manager before version 5.34.00.16 or before version 5.36 are affected. Exploitation requires local access and a low-privileged attacker account.
What level of access does an attacker need?
An attacker must already have local access to the affected system and low privileges. No user interaction is required.
What could exploitation allow?
Successful exploitation could result in information disclosure, information tampering, protection-mechanism bypass, and unauthorized access.