CVE-2026-78024 Dell Secure Connect Gateway 服务端请求伪造漏洞
影响高权限远程攻击者可利用 SSRF 获取敏感信息并绕过防护机制
Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 之前版本存在服务端请求伪造(SSRF)漏洞。攻击者可通过构造恶意请求,使服务器向任意地址发起请求,从而造成信息泄露、防护机制绕过及未授权访问。
影响范围
Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 之前的版本。
漏洞详情
该漏洞属于服务端请求伪造(SSRF),成因是应用未对用户可控的请求目标地址进行充分校验。攻击者可借此让服务器向内网或受保护资源发起请求,进而读取敏感信息、绕过访问控制或探测内部服务。
利用条件与风险
利用需要攻击者具备高权限并拥有远程访问能力,实战中多用于内网探测与敏感信息窃取,风险较高。
修复建议
建议升级至 Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 或更高版本;临时缓解措施暂无公开信息。
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Protection mechanism bypass, Server-side request forgery, and Unauthorized access.