Sceawere

Vulnerability Detail

CVE-2026-78024UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG SSRF Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
3h ago
Vendor
Dell
Product
Secure Connect Gateway (SCG) Policy Manager
Attack Type
CWE-918: Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Protection mechanism bypass, Server-side request forgery, and Unauthorized access.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-10-09T10:16:38.570Z",
  "pubdate": "2026-10-09T10:16:38.570Z",
  "executiveSummary": "Dell Secure Connect Gateway (SCG) Policy Manager versions prior to 5.34.00.16 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. This security flaw enables a remote, highly privileged attacker to manipulate the server into initiating unauthorized requests to arbitrary destinations, including internal infrastructure not accessible from the external network.\nThe vulnerability poses a significant risk to the integrity and confidentiality of the Dell SCG environment. By exploiting this flaw, an attacker can bypass security controls and protection mechanisms, potentially resulting in unauthorized access to sensitive internal resources or the exposure of configuration and operational data.\nSuccessful exploitation requires the attacker to possess high-level administrative privileges within the system, limiting the attack surface to authenticated users with significant control. Organizations utilizing Dell SCG are exposed to potential information disclosure and lateral movement risks if the gateway is leveraged to interact with other critical assets within the corporate ecosystem. Remediating this issue necessitates an immediate upgrade to the patched version, 5.34.00.16, to eliminate the underlying request handling defect.",
  "technicalDetails": "The vulnerability exists within the Dell Secure Connect Gateway (SCG) Policy Manager component, specifically relating to the improper validation of user-supplied input used to construct downstream network requests. The root cause is a failure of the application to implement strict input sanitization or whitelist-based filtering for URIs or service endpoints processed by the Policy Manager's backend logic.\nExploitation follows a predictable SSRF attack flow. An attacker with high-level administrative credentials interacts with the Policy Manager interface, providing crafted input that forces the server to initiate an outbound request to a target of the attacker's choosing. Because the server itself acts as the originator of these requests, it implicitly trusts the traffic, allowing the attacker to bypass firewall restrictions and access internal-only services, metadata APIs, or local system interfaces that are typically shielded from the public-facing gateway instance.\nThis vulnerability is classified as SSRF, but the operational impact extends to the bypass of network protection mechanisms. By routing requests through the SCG, an attacker can probe internal network topologies, perform port scanning against internal services, and potentially exploit vulnerabilities in non-public internal web applications. Furthermore, the attacker may be able to extract sensitive configuration data or tokens stored within the internal services that would otherwise be inaccessible.\nThe attack is facilitated by the high privilege level of the attacker, as the vulnerable functions are generally restricted to administrative roles. However, once the initial request is triggered, the impact is governed by the service account or network context of the SCG server itself. If the SCG runs with broad network access, the attacker's capability to traverse the internal network is greatly increased. The payload behavior involves submitting malformed parameters to the Policy Manager that instruct the backend to perform GET or POST operations against internal endpoints using various protocols (e.g., HTTP/HTTPS). Without proper egress filtering or request validation, the server acts as a proxy for the attacker's malicious activity, effectively masking the true source of the requests and circumventing existing perimeter defenses. This allows for persistent information gathering and potential escalation of privilege if the targeted internal services trust requests originating from the SCG host."
}
CVE-2026-78024: Dell SCG SSRF Vulnerability (HIGH Severity, CVSS: 7.7) | Sceawere