Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-09-29
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Elevation of Privileges
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an Incorrect Permission Assignment for a critical resource in Dell Secure Connect Gateway Policy Manager. A low privileged attacker who already has local access can exploit the improper permissions to obtain higher privileges, potentially controlling the gateway or accessing sensitive configuration data. The weakness is classified as CWE-732.

Affected Systems

Dell Secure Connect Gateway Policy Manager versions prior to 5.34.00.16 are impacted. The issue resides in the Policy Manager component used by Dell SCG deployments.

Risk and Exploitability

The CVSS score of 7.8 indicates a medium–high severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting that public exploitation is not widely documented. The exploit requires local access with a low privileged account, so an attacker would need physical or administrative access to the device before escalating privileges. Once the incorrect permissions are leveraged, the attacker could gain full control over the SCG system, leading to further compromise of the network.

Generated by OpenCVE AI on September 29, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell DSA‑2026‑385 security update to upgrade Secure Connect Gateway Policy Manager to version 5.34.00.16 or later.
  • Restrict local account usage by disabling or removing unnecessary local accounts and ensuring only trusted administrators have local access.
  • Enforce least‑privilege policies for local users by reviewing and tightening file system and configuration permissions to prevent unnecessary write access to critical resources.

Generated by OpenCVE AI on September 29, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Incorrect Permission Assignment in Dell SCG Policy Manager Enables Local Privilege Escalation

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-29T15:39:43.189Z

Reserved: 2026-08-13T11:04:26.934Z

Link: CVE-2026-73598

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:51.123

Modified: 2026-09-29T16:17:10.423

Link: CVE-2026-73598

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T17:30:17Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource