CVE-2026-73589
MEDIUMDescription
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection mechanism bypass, and Unauthorized access.
Is your site exposed to CVE-2026-73589?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| dell | policy_manager_for_secure_connect_gateway |
References
Frequently Asked Questions
What is CVE-2026-73589? +
How severe is CVE-2026-73589? +
What products are affected by CVE-2026-73589? +
How do I check if I'm vulnerable to CVE-2026-73589? +
Related Vulnerabilities
The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is …
Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password …
Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after …
The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwords within …
Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, …
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may …