CVE-2026-78019: High severity Dell Secure Connect Gateway (SCG) Policy Manager vulnerability
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Filesystem access for attacker, and Remote execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Secure Connect Gateway (SCG) Policy Managerto a version that resolves this vulnerability.Fixed in 5.34.00.16
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Exploitation requires a low-privileged attacker who already has remote access to Dell Secure Connect Gateway Policy Manager. No user interaction is required, but the attack complexity is rated high.
Which versions are affected?
Dell Secure Connect Gateway Policy Manager versions earlier than 5.34.00.16 are affected.
What could an attacker gain if exploitation succeeds?
A successful exploit could allow privilege elevation, filesystem access, and remote code execution. The reported impacts include high confidentiality, integrity, and availability effects.