CVE-2026-73599: Medium severity Dell Secure Connect Gateway (SCG) Policy Manager vulnerability
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Secure Connect Gateway (SCG) Policy Managerto a version that resolves this vulnerability.Fixed in 5.34.00.16
Event History
Frequently Asked Questions
Which deployments are affected?
Dell Secure Connect Gateway (SCG) Policy Manager versions earlier than 5.34.00.16 are affected. The provided information does not identify any configuration requirement or exception.
Does exploitation require an account or local access?
No. The vulnerability is described as exploitable by an unauthenticated attacker with remote access, although user interaction is required according to the CVSS vector.
What is the potential impact of exploitation?
Successful exploitation could lead to server-side request forgery. The supplied severity vector indicates potential low confidentiality and integrity impact, with no availability impact.