Sceawere
Vulnerability Detail
CVE-2026-73597UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG CSRF Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 13h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway (SCG) Policy Manager
- Attack Type
- CWE-352: Cross-Site Request Forgery (CSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Launch of phishing attacks, and Protection mechanism bypass.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-29T12:17:11.687Z",
"pubdate": "2026-09-29T12:17:11.687Z",
"executiveSummary": "Dell Secure Connect Gateway (SCG) Policy Manager, specifically versions prior to 5.34.00.16, is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This security flaw allows an unauthenticated, remote attacker to execute unauthorized commands or state-changing requests within the context of an authenticated user's session.\nThe vulnerability arises from insufficient validation of incoming requests, enabling attackers to trick legitimate users into performing unintended actions without their consent. The potential impact is critical, encompassing the unauthorized disclosure of sensitive system information, manipulation of configuration data, the facilitation of sophisticated phishing campaigns, and the complete bypass of established security access control mechanisms.\nGiven that the exploit is accessible to remote, unauthenticated attackers, the risk to the confidentiality, integrity, and availability of the affected system is significant. Organizations utilizing versions of Dell SCG Policy Manager prior to 5.34.00.16 are strongly advised to update to the latest provided version to neutralize this attack vector.",
"technicalDetails": "The vulnerability is a Cross-Site Request Forgery (CSRF) located within the Dell Secure Connect Gateway (SCG) Policy Manager. The root cause of this flaw is the application's failure to adequately verify the origin of state-changing requests, primarily due to the absence or improper implementation of anti-CSRF tokens (such as synchronizer tokens) or SameSite cookie attributes within the web application interface.\nThe attack flow initiates when an attacker successfully entices an authenticated user of the SCG Policy Manager to visit a malicious website or click a crafted hyperlink. Because the SCG web application fails to validate the request source, the browser automatically includes the user's session credentials (cookies or authentication tokens) with the forged request directed at the SCG Policy Manager interface.\nOnce the forged request reaches the vulnerable component, the application processes it as a legitimate action performed by the authorized user. This bypasses the intended session-based authorization checks, effectively allowing the attacker to perform any administrative or user-level task that the victim is privileged to execute.\nThe potential post-exploitation impact is extensive. By forcing the victim's browser to execute requests, the attacker can extract sensitive configuration data (Information Disclosure), alter security policies or system settings (Information Tampering), or manipulate user interface elements to facilitate deceptive social engineering campaigns (Launch of Phishing Attacks). Furthermore, if the victim possesses administrative privileges, the attacker may effectively achieve a total protection mechanism bypass, modifying access controls or disabling audit logging to maintain persistence or conceal unauthorized activities.\nThe vulnerability is present in versions prior to 5.34.00.16. Exploitation does not require the attacker to possess prior authentication credentials to the target system, as the attack relies on the existing session state of a compromised, authenticated user session. Network exposure is typically inherent to systems reachable via web protocols (HTTP/HTTPS) from the attacker's network segment. Without robust anti-CSRF protections, the SCG Policy Manager remains inherently vulnerable to any request initiated by the client browser that triggers a change in the application state."
}