Sceawere
Vulnerability Detail
CVE-2026-76114UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Cleartext Data Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 12h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway (SCG) Policy Manager
- Attack Type
- CWE-319: Cleartext Transmission of Sensitive Information
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-09-29T13:17:52.100Z",
"pubdate": "2026-09-29T13:17:52.100Z",
"executiveSummary": "Dell Secure Connect Gateway (SCG) Policy Manager, specifically versions prior to 5.34.00.16, is susceptible to a Cleartext Transmission of Sensitive Information vulnerability.\nThe vulnerability allows an unauthenticated, remote attacker to intercept sensitive data packets traversing the network in an unencrypted state.\nThis exposure undermines the confidentiality and integrity of communications handled by the Policy Manager, potentially leading to unauthorized information disclosure of sensitive gateway configurations or credentials.\nThe risk is categorized as significant due to the lack of requirement for prior authentication or elevated privileges, allowing any actor with network visibility to the SCG instance to potentially capture sensitive traffic.\nOrganizations utilizing affected Dell SCG versions are exposed to man-in-the-middle (MitM) attacks, where intercepted information could be leveraged for further reconnaissance or lateral movement within the network environment.",
"technicalDetails": "The root cause of this vulnerability lies in the implementation of network communication protocols within the Dell Secure Connect Gateway Policy Manager, where sensitive data streams are transmitted without the application of appropriate cryptographic protection, such as Transport Layer Security (TLS) or other robust encryption mechanisms.\nThe affected component is the SCG Policy Manager, which fails to enforce secure channel protocols for internal or management-related communication flows prior to version 5.34.00.16.\nAn unauthenticated attacker positioned in a network segment capable of sniffing traffic destined for or originating from the SCG instance can utilize packet capture tools to intercept cleartext data.\nThe attack flow proceeds as follows: First, the attacker identifies the SCG Policy Manager target within the local or reachable network. Second, the attacker performs passive reconnaissance or active traffic redirection (e.g., ARP spoofing or DNS poisoning) to position themselves in the communication path. Third, the attacker captures the transit data frames originating from the SCG Policy Manager. Fourth, the attacker analyzes the intercepted packets to extract sensitive credentials, session tokens, or system configuration parameters that were transmitted in plaintext.\nBecause the vulnerability does not require authentication or user interaction, the exploitation is strictly limited by the attacker’s ability to gain network access to the target gateway's communication stream. The lack of encrypted transit ensures that the payload remains human-readable or easily reversible upon interception.\nPost-exploitation impact is severe, as the disclosed information may contain credentials or configuration details that grant the attacker unauthorized access to the broader Dell SCG infrastructure, effectively bypassing secondary security controls that rely on the assumption of a secure network perimeter. By gaining access to sensitive transmission data, an attacker can further facilitate persistent presence or facilitate an escalation of access within the target management environment."
}