Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and Unauthorized access.
Published: 2026-10-09
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation and Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

Dell Secure Connect Gateway Policy Manager before version 5.34.00.16 contains an improper restriction of excessive authentication attempts flaw (CWE-307). The vulnerability permits an unauthenticated attacker with remote access to bypass protection mechanisms, elevate privileges, and gain unauthorized access to the system.

Affected Systems

The flaw affects Dell Secure Connect Gateway Policy Manager products, specifically all versions earlier than 5.34.00.16.

Risk and Exploitability

The CVSS rating of 7.4 signals a high severity vulnerability, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the issue remotely without authentication, making the potential impact significant. The lack of EPSS data indicates uncertainty about current exploit prevalence, but the high CVSS suggests that if exploited, the attacker could gain elevated privileges and bypass protective controls.

Generated by OpenCVE AI on October 9, 2026 at 09:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell’s official security update to version 5.34.00.16 or later to resolve the authentication restriction flaw.
  • Limit remote access to the Policy Manager by enforcing VPN or secure channel policies, thereby reducing exposure to unauthenticated remote attackers.
  • Implement rate‑limiting or account lockout rules on the Policy Manager where possible to mitigate brute‑force attempts and enforce the restriction of excessive authentication attempts.

Generated by OpenCVE AI on October 9, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Restriction of Excessive Authentication Attempts in Dell Secure Connect Gateway Policy Manager

Fri, 09 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and Unauthorized access.
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-10-09T08:22:40.495Z

Reserved: 2026-08-19T17:05:19.872Z

Link: CVE-2026-76779

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T09:17:08.430

Modified: 2026-10-09T09:17:08.430

Link: CVE-2026-76779

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:30:03Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts