PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73589 Dell CVE debrief

A low-privileged attacker with local access could potentially exploit the Weak Encoding for Password vulnerability in Dell Secure Connect Gateway (SCG) Policy Manager versions prior to 5.34.00.16 and versions prior to 5.36, leading to information disclosure, information tampering, protection mechanism bypass, and unauthorized access. This vulnerability requires medium-priority defensive actions to prevent local attackers from exploiting it for various malicious activities. System administrators and security teams should assess exposure and apply the security update provided by Dell.

Vendor
Dell
Product
Secure Connect Gateway (SCG) Policy Manager
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-23
Original CVE updated
2026-09-25
Advisory published
2026-09-23
Advisory updated
2026-09-25

Who should care

System administrators and security teams responsible for Dell Secure Connect Gateway (SCG) Policy Manager systems should assess exposure and apply the security update provided by Dell. Local attackers could exploit this vulnerability for information disclosure, tampering, protection bypass, and unauthorized access.

Why it matters

The Weak Encoding for Password vulnerability in Dell Secure Connect Gateway (SCG) Policy Manager requires medium-priority defensive actions to prevent local attackers from exploiting the vulnerability for information disclosure, tampering, protection bypass, and unauthorized access.

  • Information disclosure: attackers may access sensitive information.
  • Information tampering: attackers may modify sensitive information.
  • Protection mechanism bypass: attackers may bypass security controls.
  • Unauthorized access: attackers may gain unauthorized access to systems.

Technical summary

The Dell Secure Connect Gateway (SCG) Policy Manager contains a Weak Encoding for Password vulnerability in versions prior to 5.34.00.16 and versions prior to 5.36. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure, information tampering, protection mechanism bypass, and unauthorized access. The vulnerability is related to weak encoding for passwords, which could allow attackers to gain unauthorized access to sensitive information. Defensive actions should focus on applying security updates, restricting local access, and implementing additional security measures.

Defensive priority

Medium-priority defensive actions are recommended to address the Weak Encoding for Password vulnerability in Dell Secure Connect Gateway (SCG) Policy Manager. Local attackers could exploit this vulnerability for information disclosure, tampering, protection bypass, and unauthorized access.

Recommended defensive actions

  • Review and apply the security update provided by Dell for Policy Manager versions prior to 5.34.00.16 and versions prior to 5.36.
  • Restrict local access to Policy Manager systems to trusted users only.
  • Monitor Policy Manager systems for unauthorized access and information tampering.
  • Consider implementing additional security measures such as encryption and secure authentication mechanisms.
  • Perform a thorough review of system configurations and user access controls.
  • Implement monitoring and detection mechanisms to identify potential security incidents.
  • Keep software and systems up-to-date with the latest security patches.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Dell has released a security update for the affected Policy Manager versions. The vulnerability has been identified in versions prior to 5.34.00.16 and versions prior to 5.36 of Dell Secure Connect Gateway (SCG) Policy Manager. Evidence is based on CVE and NVD information, with limitations on source-provided details. Defenders should verify affected systems and apply patches accordingly.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73589 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73589

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73589 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73589

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.