Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Less Trusted Source vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
Published: 2026-10-09
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: Information Tampering
Action: Apply Patch
AI Analysis

Impact

This vulnerability arises from a Use of Less Trusted Source condition that allows an unauthenticated attacker with remote access to potentially alter configuration information within the Dell Secure Connect Gateway Policy Manager. The impact is limited to information tampering—data integrity could be compromised if an attacker modifies policy settings. No denial of service or code execution is indicated by the current description.

Affected Systems

Affected are Dell Secure Connect Gateway Policy Manager installations running any version prior to 5.34.00.16. The product is delivered by Dell under the Secure Connect Gateway umbrella and deployed by organizations that require secure remote access gateways.

Risk and Exploitability

The CVSS score of 3.7 reflects a moderate severity, primarily due to lack of authentication and limited impact. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting low exploitation likelihood. Attackers would need remote network-level access to the SCG or a path to reach the Policy Manager exposed over the internet or an internal network. In the absence of authentication, a determined attacker could manipulate policies once they reach the vulnerable component, but the overall risk is considered limited compared to higher severity exploits.

Generated by OpenCVE AI on October 9, 2026 at 09:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Dell Secure Connect Gateway Policy Manager version 5.34.00.16 or later, which contains the vendor‑supplied fix for this use‑of‑less‑trusted‑source issue.
  • If upgrading is not immediately feasible, restrict remote access to the Policy Manager and enforce strict firewall rules to prevent unauthenticated traffic from reaching the gateway.
  • Continuously monitor configuration change logs for unexpected policy alterations, and audit the gateway to detect tampering attempts.

Generated by OpenCVE AI on October 9, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Title Use of Less Trusted Source Vulnerability in Dell Secure Connect Gateway Policy Manager Leading to Information Tampering

Fri, 09 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Less Trusted Source vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
Weaknesses CWE-348
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-10-09T08:30:01.082Z

Reserved: 2026-08-21T23:04:41.425Z

Link: CVE-2026-78015

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T09:17:08.680

Modified: 2026-10-09T09:17:08.680

Link: CVE-2026-78015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:30:03Z

Weaknesses
  • CWE-348

    Use of Less Trusted Source