Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-09-23
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access
Action: Apply Patch
AI Analysis

Impact

Dell Secure Connect Gateway (SCG) Policy Manager suffers from an Improper Privilege Management flaw that can be triggered by a low‑privileged attacker who has remote access to the device. The deficiency in privilege checks can allow the attacker to gain unauthorized access to administrative functions, thereby potentially enabling the modification of security policies, viewing of confidential configuration data, or disruption of service availability. The vulnerability arises from insufficient enforcement of privilege levels, exposing the system to unauthorized manipulation of its configuration and operation.

Affected Systems

Dell Secure Connect Gateway (SCG) Policy Manager deployments running versions earlier than 5.34.00.16. The flaw exists across all releases that predate the stated version and affects the product’s default configuration for remote management interfaces.

Risk and Exploitability

The flaw carries a CVSS base score of 6.8, indicating moderate impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests no widespread exploitation to date. Based on the description, the likely attack vector is remote exploitation via the device’s management interface that can be accessed by operators with low privilege, such as guest or limited‑role accounts. An attacker would need remote connectivity to the device, though no specific network prerequisites are noted beyond general remote access.

Generated by OpenCVE AI on September 23, 2026 at 16:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway Policy Manager security update for all affected versions, which is available on Dell’s support site (https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9).
  • Restrict remote management access by configuring firewall rules or device settings to allow only trusted IP ranges, thereby limiting exposure of the management interface.
  • Implement strict role‑based access control, ensuring that low‑privileged accounts lack administrative rights and that privilege escalation paths are closed.

Generated by OpenCVE AI on September 23, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-23T16:19:44.299Z

Reserved: 2026-07-09T11:05:01.706Z

Link: CVE-2026-61413

cve-icon Vulnrichment

Updated: 2026-09-23T16:19:39.439Z

cve-icon NVD

Status : Received

Published: 2026-09-23T15:17:14.867

Modified: 2026-09-23T17:17:15.723

Link: CVE-2026-61413

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T16:15:06Z

Weaknesses
  • CWE-269

    Improper Privilege Management