Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Information tampering, Protection mechanism bypass, and Unauthorized access.
Published: 2026-09-29
Score: 3.8 Low
EPSS: n/a
KEV: No
Impact: Privilege Escalation and Unauthorized Access
Action: Apply Patch
AI Analysis

Impact

The vulnerability in Dell Secure Connect Gateway (SCG) Policy Manager is an Initialization of a Resource with an Insecure Default, listed as CWE-1188. An attacker with high privileges and remote access can leverage this flaw to elevate privileges, tamper with information, bypass protection mechanisms, and gain unauthorized access. The impact can compromise the integrity and confidentiality of the system and enable further malicious actions by the compromised account.

Affected Systems

The affected product is Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16. All installations of these versions are vulnerable unless updated to the latest release.

Risk and Exploitability

The CVSS score of 3.8 indicates a low severity, and the EPSS score is not available, suggesting limited publicly known exploits. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires a high privileged attacker with remote access and is inferred from the description; the system must be accessed remotely to exploit the insecure initialization.

Generated by OpenCVE AI on September 30, 2026 at 03:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Security Update for SCG Policy Manager version 5.34.00.16 or later to eliminate the insecure initialization weakness.
  • If an update cannot be applied immediately, limit remote access to the SCG Policy Manager and enforce the principle of least privilege to reduce the attacker's capabilities.
  • Monitor for signs of unauthorized privilege escalation or tampering and prepare an incident response plan to address any detected activity.

Generated by OpenCVE AI on September 30, 2026 at 03:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title Dell SCG Policy Manager Insecure Initialization Vulnerability Allowing Privilege Escalation

Tue, 29 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Dell SCG Policy Manager Insecure Initialization Vulnerability Allowing Privilege Escalation

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Information tampering, Protection mechanism bypass, and Unauthorized access.
Weaknesses CWE-1188
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-30T03:56:00.123Z

Reserved: 2026-08-13T11:04:26.934Z

Link: CVE-2026-73596

cve-icon Vulnrichment

Updated: 2026-09-29T15:37:05.132Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T12:17:11.557

Modified: 2026-09-30T04:18:31.163

Link: CVE-2026-73596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T03:45:17Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default