Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft.
Published: 2026-09-23
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Elevation of Privileges and Session Theft
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an Improper Restriction of Rendered UI Layers or Frames flaw in Dell Secure Connect Gateway Policy Manager. Remote attackers with low privileged access can manipulate the rendering environment, which may allow them to elevate privileges and potentially steal user sessions. The flaw exists because the appliance does not enforce proper boundaries between UI layers or frames.

Affected Systems

Dell Secure Connect Gateway (SCG) Policy Manager versions earlier than 5.34.00.16 are affected. The issue resides in the Policy Manager component of the appliance.

Risk and Exploitability

The CVSS score of 5.4 indicates medium severity. EPSS data is not available, and the vulnerability is not listed in DSA KEV, suggesting no known exploit at present. An attacker must first obtain low‑privileged remote access to the device before the flaw can be leveraged, which raises the practical risk to moderate levels compared to higher‑privilege exploits.

Generated by OpenCVE AI on September 23, 2026 at 16:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell’s Security Advisory update to bring Secure Connect Gateway Policy Manager to version 5.34.00.16 or later.
  • Restrict remote network access to the Policy Manager appliance to trusted administrators only, enforcing least‑privilege controls.
  • Monitor login and UI activity logs for signs of unauthorized session theft or privilege escalation attempts.

Generated by OpenCVE AI on September 23, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Improper UI Layer Restriction Allows Privilege Elevation and Session Theft in Dell Secure Connect Gateway Policy Manager
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft.
Weaknesses CWE-1021
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-23T15:23:06.288Z

Reserved: 2026-08-04T23:04:32.436Z

Link: CVE-2026-71177

cve-icon Vulnrichment

Updated: 2026-09-23T15:23:00.511Z

cve-icon NVD

Status : Received

Published: 2026-09-23T15:17:16.457

Modified: 2026-09-23T16:16:44.080

Link: CVE-2026-71177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T16:15:06Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames