天下漏洞,尽知其名
HIGH

CVE-2026-78019 Dell Secure Connect Gateway 权限提升漏洞

影响低权限远程攻击者可提升权限并执行任意代码

AI 研判

Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 之前版本存在来自不可信控制域的功能包含漏洞(CWE-829)。低权限攻击者可通过远程访问利用该漏洞,实现权限提升、文件系统访问及远程代码执行。

影响范围

Dell Secure Connect Gateway

Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 之前的版本。

漏洞详情

该漏洞属于从不可信控制域包含功能(Inclusion of Functionality from Untrusted Control Sphere),即程序加载或执行了来自不受信任来源的功能代码。攻击者可借此绕过权限边界,读取或操作文件系统,并进一步在目标主机上执行任意代码。

利用条件与风险

利用需要攻击者具备远程访问能力且拥有低权限账户,但一旦成功即可提升权限并远程执行代码,实战风险较高。

修复建议

建议升级至 Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 或更高版本;临时缓解措施暂无公开信息。

原始情报

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Filesystem access for attacker, and Remote execution.