Sceawere
Vulnerability Detail
CVE-2026-73595UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Insecure Code Download
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 13h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway (SCG) Policy Manager
- Attack Type
- CWE-494: Download of Code Without Integrity Check
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Code execution, Information disclosure, Information tampering, and Protection mechanism bypass.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-09-29T12:17:11.427Z",
"pubdate": "2026-09-29T12:17:11.427Z",
"executiveSummary": "Dell Secure Connect Gateway (SCG) Policy Manager is susceptible to a 'Download of Code Without Integrity Check' vulnerability, categorized as an improper validation of file authenticity. The flaw resides in the handling of externally sourced files, allowing an unauthenticated remote attacker to bypass security mechanisms.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the affected gateway. Successful exploitation permits an attacker to execute arbitrary code with the privileges of the application, potentially leading to unauthorized data disclosure, modification of sensitive configurations, and complete system compromise.\nThe vulnerability affects Dell SCG Policy Manager versions prior to 5.34.00.16 and versions prior to 5.36. Because the exploit does not require authentication, the risk profile is elevated for any instance exposed to network access. Remediation requires an immediate upgrade to the patched versions provided by Dell to restore integrity controls.",
"technicalDetails": "The core vulnerability stems from the Dell SCG Policy Manager's failure to perform cryptographic signature verification or checksum validation on downloaded code payloads. By omitting these essential integrity checks, the application implicitly trusts files retrieved from remote sources, assuming they are authentic and unmodified.\nThe attack flow begins with an unauthenticated remote actor intercepting or manipulating the communication channel between the Policy Manager and a remote resource. When the gateway initiates a request to download updates, configuration files, or modular components, the attacker can perform a Man-in-the-Middle (MitM) attack to intercept the transmission. Alternatively, if the resource repository is compromised or spoofed, the attacker can serve a malicious binary package in place of a legitimate one.\nBecause the SCG Policy Manager lacks a validation routine to verify the origin or integrity of the ingested data, it proceeds to execute, load, or process the malicious payload. This behavior bypasses the protection mechanisms intended to ensure that only cryptographically signed Dell-authorized code is executed by the system.\nUpon successful execution of the payload, the attacker achieves arbitrary code execution. Given the context of the Policy Manager, this often implies elevated operational permissions, facilitating post-exploitation activities such as exfiltrating proprietary system information, modifying security policies, or establishing persistence on the gateway appliance. This leads to information tampering and a complete bypass of the platform's security architecture.\nThe vulnerability impacts Dell SCG Policy Manager versions prior to 5.34.00.16 and versions prior to 5.36. The absence of authentication and privilege requirements for the initial exploitation vector makes the device highly susceptible to network-based attacks. The threat is most pronounced in environments where the gateway communicates over insecure channels or where the resolution of external update servers is susceptible to DNS poisoning or redirection."
}