CVE-2026-73595: Medium severity Dell Secure Connect Gateway (SCG) Policy Manager vulnerability
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Code execution, Information disclosure, Information tampering, and Protection mechanism bypass.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Secure Connect Gateway (SCG) Policy Managerto a version that resolves this vulnerability.Fixed in 5.34.00.16 - Upgrade
Upgrade
Dell Secure Connect Gateway (SCG) Policy Managerto a version that resolves this vulnerability.Fixed in 5.36
Event History
Frequently Asked Questions
Does exploitation require user interaction?
Yes. The CVSS vector indicates user interaction is required for exploitation.
How difficult is exploitation expected to be?
The CVSS vector rates attack complexity as high, indicating exploitation depends on conditions beyond simply reaching the affected service.
Is service availability expected to be affected?
No availability impact is indicated in the CVSS vector. The listed impacts are limited confidentiality and integrity effects.