Dell TechnologiesCVE-2026-73597
Dell Technologies Secure Connect: cross-site request forgery
Medium6.5CVE-2026-73597 · Published Sep 29, 2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Launch of phishing attacks, and Protection mechanism bypass.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Secure Connect Gateway (SCG) Policy Manager Product | < 5.36.00.16 or later | 5.36.00.16 or later |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-352
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 29 | Dell Technologies Secure Connect Gateway (SCG) Policy Manager: cleartext secrets | Medium5.9 | 5.36.00.16 or later |
| Sep 29 | Dell Technologies Secure Connect Gateway Policy Manager: insecure permissions | High7.8 | 5.36.00.16 or later |
| Sep 29 | Dell Technologies Secure Connect Gateway (SCG) Policy Manager: open redirect | Medium5.4 | 5.36.00.16 or later |
| Sep 29 | Dell Technologies Secure Connect Gateway Policy Manager: information disclosure | Low3.0 | 5.36.00.16 or later |
| Sep 29 | Dell Technologies Secure Connect: improper certificate validation | Medium6.4 | 5.36.00.16 or later |
| Sep 29 | Dell Technologies Secure Connect Gateway Policy Manager: remote code execution | Medium4.7 | 5.36.00.16 or later |