Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Protection mechanism bypass.
Published: 2026-10-09
Score: 5.2 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an initialization of a resource with an insecure default in Dell Secure Connect Gateway Policy Manager. Because of this flaw, a high privileged attacker who has local access can trigger a denial of service, disclose confidential information, and bypass protection mechanisms. The weakness corresponds to CWE-1188, which highlights failure to set secure defaults during resource initialization.

Affected Systems

Affected systems are Dell Secure Connect Gateway Policy Managers running any version earlier than 5.34.00.16. The vulnerability is present in all such installations regardless of configuration, providing a broad attack surface to local privileged users.

Risk and Exploitability

The CVSS score of 5.2 indicates moderate severity, and the EPSS score is currently unavailable, making it unclear how often this flaw is actively exploited. Because exploitation requires high privileged local access, the attack surface is limited to administrators or technicians with physical or remote privileged rights. As the vulnerability is not listed in the CISA KEV catalog, no known exploit code is publicly documented at this time.

Generated by OpenCVE AI on October 9, 2026 at 09:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell's security update for Secure Connect Gateway Policy Manager to version 5.34.00.16 or later.
  • Restrict local access to the device and enforce least privilege for accounts that can communicate with the policy manager.
  • Review and adjust any custom initialization parameters to ensure secure defaults are enforced.

Generated by OpenCVE AI on October 9, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Protection mechanism bypass.
Weaknesses CWE-1188
References
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-10-09T08:26:10.050Z

Reserved: 2026-08-21T23:04:41.425Z

Link: CVE-2026-78013

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T09:17:08.557

Modified: 2026-10-09T09:17:08.557

Link: CVE-2026-78013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:30:03Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default