Sceawere

Vulnerability Detail

CVE-2026-73599UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG Open Redirect Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
12h ago
Vendor
Dell
Product
Secure Connect Gateway (SCG) Policy Manager
Attack Type
CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-29T13:17:51.763Z",
  "pubdate": "2026-09-29T13:17:51.763Z",
  "executiveSummary": "Dell Secure Connect Gateway (SCG) Policy Manager versions prior to 5.34.00.16 are susceptible to an 'Open Redirect' vulnerability categorized under URL Redirection to Untrusted Site. This flaw permits an unauthenticated, remote attacker to manipulate URL parameters to force the application to redirect users or perform server-side requests to arbitrary, untrusted domains.\nThe primary risk associated with this vulnerability is Server-Side Request Forgery (SSRF), which may allow an attacker to bypass internal network protections, interact with restricted services within the Dell SCG infrastructure, or facilitate phishing campaigns by abusing the trusted domain of the gateway. The vulnerability does not require authentication, significantly lowering the barrier to entry for potential adversaries. Successful exploitation could lead to unauthorized information disclosure or further compromise of the management infrastructure. Organizations are advised to update to the specified secure version to remediate the underlying flaw.",
  "technicalDetails": "The vulnerability resides within the Policy Manager component of Dell Secure Connect Gateway (SCG). The root cause is an improper validation of user-supplied input provided to parameters responsible for redirecting traffic or initiating outbound connections. Because the application fails to enforce an allow-list of permissible domains or validate the destination URL structure, it manifests as an 'Open Redirect' that enables Server-Side Request Forgery (SSRF).\nIn a typical attack flow, the adversary identifies a URL parameter within the Policy Manager web interface that handles redirection logic. By injecting a crafted URL pointing to an attacker-controlled endpoint or an internal service, the attacker can leverage the server's context to perform requests. Since the SCG server initiates these requests, the traffic appears to originate from a trusted internal source, often bypassing perimeter firewalls or IP-based access control lists (ACLs) that protect internal segments.\nThe vulnerability affects Dell Secure Connect Gateway (SCG) Policy Manager versions prior to 5.34.00.16. Exploitation is possible without prior authentication, and the vulnerability is exposed to any remote user capable of reaching the Policy Manager web interface. When a malicious payload is processed, the server may perform a GET or POST request to the target specified in the input parameter. If the target is an internal management service, the attacker may gain access to sensitive API endpoints or data that are otherwise inaccessible from the public internet.\nPost-exploitation impact includes the potential for reconnaissance of the internal network architecture, retrieval of configuration metadata, or the execution of unauthorized actions against other integrated services. The lack of strict output sanitization or URL normalization allows the adversary to obfuscate the destination, potentially bypassing simple security filters. Because the SCG acts as a central hub for telemetry and management, an SSRF condition here represents a critical pivot point for lateral movement within the network. Effective remediation requires upgrading the software to version 5.34.00.16 or later, which includes refined logic to enforce destination origin constraints and prevent unauthorized external requests."
}
CVE-2026-73599: Dell SCG Open Redirect Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere