天下漏洞,尽知其名
HIGH

CVE-2026-78023 Dell Secure Connect Gateway 授权绕过漏洞

影响低权限远程攻击者可绕过授权提升权限

AI 研判

Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 之前版本存在授权绕过漏洞(通过用户可控密钥实现,即 IDOR 类问题)。低权限攻击者可通过远程访问利用该漏洞,实现权限提升。

影响范围

Dell Secure Connect Gateway

Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 之前的版本。

漏洞详情

漏洞类型为通过用户可控密钥导致的授权绕过(Authorization Bypass Through User-Controlled Key),属于访问控制缺陷。程序在处理请求时直接信任用户可控的标识(如 ID、密钥等),未校验其归属与权限,导致低权限用户可访问或操作本应属于更高权限用户的资源。攻击者通过构造或篡改该密钥参数即可越权执行操作,进而提升自身权限。

利用条件与风险

利用前提是攻击者已具备低权限账户并能远程访问 SCG Policy Manager 服务;一旦成功即可越权提升权限,对受管设备与策略配置构成较高风险。

修复建议

官方修复方案为升级至 5.34.00.16 或更高版本;临时缓解措施暂无公开信息,建议限制服务网络暴露面并遵循最小权限原则。

原始情报

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.