CVE-2026-73597: CSRF
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Launch of phishing attacks, and Protection mechanism bypass.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Secure Connect Gateway (SCG) Policy Managerto a version that resolves this vulnerability.Fixed in 5.34.00.16
Event History
Frequently Asked Questions
Which installations need remediation?
Dell Secure Connect Gateway (SCG) Policy Manager versions earlier than 5.34.00.16 are affected. Version 5.34.00.16 or later is not identified as affected in the provided advisory data.
Does exploitation require an authenticated account or user interaction?
The vulnerability is described as exploitable by an unauthenticated remote attacker, and the vector indicates no privileges or user interaction are required. The attacker must have remote network access to the affected system.
What could successful exploitation allow?
Successful exploitation could lead to information disclosure, information tampering, phishing attacks, or protection-mechanism bypass. Availability impact is listed as none.