{"id":"CVE-2026-73587","title":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability","summary":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerabil…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-295"],"vendor":"Dell","product":"Secure Connect Gateway (SCG) Policy Manager","affected":["secure_connect_gateway_scg_policy_manager < 5.36.00.16 or later"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T17:58:26.570","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73587","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"security_alert@emc.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-23T16:22:04.726800Z"},"ingestedAt":"2026-09-23T14:25:29.806Z","slug":"CVE-2026-73587","body":"## Overview\n\nDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Protection mechanism bypass.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}