Sceawere
Vulnerability Detail
CVE-2026-78341UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Incorrect Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway (SCG) Policy Manager
- Attack Type
- CWE-863: Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-09T10:16:39.387Z",
"pubdate": "2026-10-09T10:16:39.387Z",
"executiveSummary": "Dell Secure Connect Gateway (SCG) Policy Manager versions prior to 5.34.00.16 are susceptible to an Incorrect Authorization vulnerability. This security flaw enables a remote attacker, who already possesses high-privileged access, to perform unauthorized actions or escalate their privileges beyond their current authorization scope.\nThe vulnerability resides within the authorization logic of the Policy Manager component. By exploiting this flaw, an attacker can bypass intended security controls that restrict administrative or system-level operations. The risk implication is significant, as it could allow for unauthorized system manipulation, potentially compromising the integrity and confidentiality of the gateway environment.\nSuccessful exploitation requires the attacker to have established remote access and high-privileged credentials prior to the attempt. Because the vulnerability involves an authorization failure, the impact is localized to the operational capabilities of the Policy Manager, though the resulting elevation of privilege grants the actor unauthorized access to restricted functions. Dell has addressed this issue by releasing version 5.34.00.16, which corrects the improper authorization logic.",
"technicalDetails": "The vulnerability is classified as an Incorrect Authorization issue within the Dell Secure Connect Gateway (SCG) Policy Manager. The root cause pertains to an flaw in the application's access control enforcement mechanism, which fails to properly validate the authorization context when processing requests within the Policy Manager component.\nIn the affected versions (prior to 5.34.00.16), the Policy Manager does not sufficiently verify that a requestor’s high-privileged session maintains the appropriate authorization scope to execute specific sensitive operations. While the attacker must be authenticated and maintain high-level access to the environment, the vulnerability allows this attacker to bypass secondary authorization checks that are intended to compartmentalize administrative tasks.\nThe attack flow initiates with a remote attacker leveraging existing high-privileged credentials to establish a session with the SCG. Once authenticated, the attacker targets the Policy Manager interface or its underlying API endpoints. By crafting specific requests that deviate from standard operational workflows, the attacker triggers the flawed authorization logic. Because the system fails to correctly validate the permissions mapped to the user session against the requested resource, the Policy Manager incorrectly grants access to perform restricted actions that would otherwise be prohibited.\nThe technical impact is an elevation of privilege, where the attacker can escalate from a restricted administrative level to broader, unauthorized control over the SCG environment. This could include the modification of security policies, alteration of configuration settings, or unauthorized access to sensitive telemetry data handled by the gateway. The payload behavior is characterized by the invocation of legitimate but unauthorized API calls or functions that are incorrectly permitted due to the bypass. The post-exploitation impact includes the potential for total system compromise, exfiltration of stored information, or the modification of security routing configurations. The flaw is confined to the software's internal authorization routines and necessitates network connectivity to the target SCG instance."
}