Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Filesystem access for attacker, and Remote execution.
Published: 2026-10-09
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Dell Secure Connect Gateway (SCG) Policy Manager contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability that enables a low‑privileged attacker with remote access to elevate privileges, gain filesystem access, and execute code on the host. The weakness, classified as CWE‑829, permits the attacker to activate internal functions that were not intended to be exposed to untrusted inputs, effectively turning the system into a conduit for malicious actions.

Affected Systems

Affected by this vulnerability are all Dell Secure Connect Gateway Policy Manager installations running versions older than 5.34.00.16. The issue does not affect newer releases, so upgrading to a version that includes the Dell security update is required to resolve the problem.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, though the EPSS score is not available, implying limited data on current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need remote network connectivity to the SCG and only low privileged credentials, so the risk is elevated for systems exposed to untrusted networks. The potential for remote execution makes this a critical threat if not remediated promptly.

Generated by OpenCVE AI on October 9, 2026 at 10:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell’s security update DSA-2026-385 to secure the SCG Policy Manager and upgrade to at least version 5.34.00.16.
  • If an immediate update is not feasible, limit remote access to the SCG by applying firewall rules or network segmentation to minimize attacker reach, and enforce strict authentication controls.
  • Continuously monitor authentication logs and privilege‑elevation events for anomalous activity to detect exploitation attempts early.

Generated by OpenCVE AI on October 9, 2026 at 10:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Filesystem access for attacker, and Remote execution.
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-10-09T08:45:38.969Z

Reserved: 2026-08-21T23:04:41.426Z

Link: CVE-2026-78019

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T09:17:09.177

Modified: 2026-10-09T09:17:09.177

Link: CVE-2026-78019

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T10:45:05Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere