Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Published: 2026-09-23
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Information Exposure
Action: Apply Patch
AI Analysis

Impact

Dell Secure Connect Gateway (SCG) Policy Manager versions older than 5.34.00.16 contain an inclusion of sensitive information in source code that an unauthenticated remote attacker could exploit, resulting in exposure of confidential data. The vulnerability is classified as CWE-540 and carries a CVSS score of 7.5, describing a moderate to high severity risk to confidentiality.

Affected Systems

The affected product is Dell Secure Connect Gateway Policy Manager provided by Dell. Versions prior to 5.34.00.16 are vulnerable; any installation running those releases may be compromised if exposed to remote access.

Risk and Exploitability

The absence of an EPSS score limits precise exploitation probability, but the lack of authentication requirement means any remote user could potentially read the exposed data. The vulnerability is not listed in the CISA KEV catalog, yet the high CVSS indicates a substantial risk. Enterprise administrators should treat the exposure as a serious confidentiality breach and prioritize remediation.

Generated by OpenCVE AI on September 23, 2026 at 16:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Dell Secure Connect Gateway (SCG) Policy Manager update that removes the sensitive source code.
  • Confirm the device is running version 5.34.00.16 or later; if not, upgrade immediately.
  • Restrict remote management access to trusted internal networks and enforce strong authentication controls.

Generated by OpenCVE AI on September 23, 2026 at 16:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Weaknesses CWE-540
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-23T14:34:43.284Z

Reserved: 2026-08-13T11:04:26.934Z

Link: CVE-2026-73591

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T15:17:18.103

Modified: 2026-09-23T15:17:18.103

Link: CVE-2026-73591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T16:45:03Z

Weaknesses
  • CWE-540

    Inclusion of Sensitive Information in Source Code