← All Advisories

CVE-2026-73591

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-73591

Key Details

CVECVE-2026-73591
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productsdell policy_manager_for_secure_connect_gateway and dell Secure Connect Gateway (SCG) Policy Manager
Classified asCWE-540 (Inclusion of Sensitive Information in Source Code)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
dellpolicy_manager_for_secure_connect_gateway
dellSecure Connect Gateway (SCG) Policy Manager
SubsystemsGeneral OT
SectorsMultiple

What to Know

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. (NVD)

What to Do

Monitor dell's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-73591
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-73591
Vendor advisoryhttps://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9