Dell TechnologiesCVE-2026-73595
Dell Technologies Secure Connect Gateway Policy Manager: remote code execution
Medium4.7CVE-2026-73595 · Published Sep 29, 2026 · updated Sep 30, 2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Code execution, Information disclosure, Information tampering, and Protection mechanism bypass.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Secure Connect Gateway (SCG) Policy Manager Product | < 5.36.00.16 or later | 5.36.00.16 or later |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-494
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | Dell Technologies Secure Connect Gateway (SCG) Policy Manager: cleartext secrets | Medium5.9 | 5.36.00.16 or later |
| Sep 29 | Dell Technologies Secure Connect Gateway Policy Manager: insecure permissions | High7.8 | 5.36.00.16 or later |
| Sep 29 | Dell Technologies Secure Connect Gateway (SCG) Policy Manager: open redirect | Medium5.4 | 5.36.00.16 or later |
| Sep 29 | Dell Technologies Secure Connect Gateway Policy Manager: information disclosure | Low3.0 | 5.36.00.16 or later |
| Sep 29 | Dell Technologies Secure Connect: improper certificate validation | Medium6.4 | 5.36.00.16 or later |
| Sep 29 | Dell Technologies Secure Connect Gateway (SCG) Policy Manager: tampering | Low3.8 | 5.36.00.16 or later |