CVE-2026-78340: Path Traversal
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Filesystem access for attacker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Secure Connect Gateway (SCG) Policy Managerto a version that resolves this vulnerability.Fixed in 5.34.00.16
Event History
Frequently Asked Questions
Who is realistically exposed to this vulnerability?
Systems running Dell Secure Connect Gateway (SCG) Policy Manager versions earlier than 5.34.00.16 are affected. Exploitation requires local access and high privileges, so remote-only unauthenticated attackers are not described as an exposure path.
What access does an attacker need to exploit it?
The attacker must have local access, high privileges, and user interaction is required according to the supplied CVSS vector. Successful exploitation could result in code execution and filesystem access.
What is the remediation?
Update Dell Secure Connect Gateway (SCG) Policy Manager to version 5.34.00.16 or later. The provided data does not specify alternative mitigations if updating cannot be completed immediately.