← All Advisories

CVE-2026-73588

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-73588

Key Details

CVECVE-2026-73588
CVSS Score / Version7.4 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsdell policy_manager_for_secure_connect_gateway and dell Secure Connect Gateway (SCG) Policy Manager
Classified asCWE-306 (Missing Authentication for Critical Function)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
dellpolicy_manager_for_secure_connect_gateway
dellSecure Connect Gateway (SCG) Policy Manager
SubsystemsGeneral OT
SectorsMultiple

What to Know

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. (NVD)

What to Do

Monitor dell's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-73588
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-73588
Vendor advisoryhttps://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9