CVE-2026-73595
Received Received - Intake

Dell Secure Connect Gateway Policy Manager Code Execution Vulnerability

Vulnerability report for CVE-2026-73595, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Dell

Description

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Code execution, Information disclosure, Information tampering, and Protection mechanism bypass.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
dell secure_connect_gateway to 5.34.00.16 (exc)
dell secure_connect_gateway to 5.36 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-494 The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Dell Secure Connect Gateway (SCG) Policy Manager before version 5.34.00.16 or 5.36 has a flaw where it does not verify the integrity of downloaded code. This allows an unauthenticated remote attacker to execute arbitrary code, disclose sensitive information, tamper with data, or bypass security protections.

Impact Analysis

An attacker could gain control over the system, steal confidential data, alter system behavior, or disable security features without needing to authenticate. This could lead to further network compromise or data breaches.

Compliance Impact

This vulnerability could potentially lead to information disclosure and tampering, which may violate GDPR's data protection requirements and HIPAA's safeguards for protected health information. Unauthorized access or modification of data could result in non-compliance with these regulations.

Mitigation Strategies

Update Dell Secure Connect Gateway (SCG) Policy Manager to version 5.34.00.16 or later, or to version 5.36 or later if available. This addresses the Download of Code Without Integrity Check vulnerability by ensuring integrity checks are enforced.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73595. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart