Skip to content
dell-technologiesCVE-2026-73589

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability.

Medium6.3CVE-2026-73589 · Published Sep 23, 2026 · updated Sep 25, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Secure Connect Gateway (SCG) Policy Manager
Vendor
< 5.36.00.16 or later5.36.00.16 or later
Details and references

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection mechanism bypass, and Unauthorized access.

CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
no source yet
Weakness
CWE-261

More dell-technologies advisories

All
DateAdvisory
Sep 23Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability.
CVE-2026-61413Medium6.8fixed in Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later
Sep 23Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability.
CVE-2026-71177Medium5.4fixed in Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later
Sep 23Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability.
CVE-2026-71178Low3.7fixed in Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later
Sep 23Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability.
CVE-2026-73586Medium6.4fixed in Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later
Sep 23Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability.
CVE-2026-73587Medium6.8fixed in Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later
Sep 23Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability.
CVE-2026-73588High7.4fixed in Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.