天下漏洞,尽知其名
HIGH

CVE-2026-78025 Dell Secure Connect Gateway 关键功能缺失认证漏洞

影响未认证远程攻击者可绕过防护并获取敏感信息

AI 研判

Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 之前版本存在关键功能缺失认证漏洞。未认证的远程攻击者可利用该漏洞绕过保护机制,导致信息泄露和未授权访问。

影响范围

Dell Secure Connect Gateway

Dell Secure Connect Gateway (SCG) Policy Manager 5.34.00.16 之前的版本。

漏洞详情

该漏洞属于关键功能缺失身份认证(Missing Authentication for Critical Function)类型,成因是产品对某些关键功能接口未实施必要的身份验证校验。攻击者无需任何凭据即可通过网络远程访问这些接口,从而绕过保护机制、读取敏感信息或执行未授权操作。

利用条件与风险

利用前提为攻击者能够远程访问受影响服务,无需认证即可触发,实战中可能导致敏感信息泄露与系统未授权访问,风险较高。

修复建议

建议升级至 5.34.00.16 或更高版本;在无法立即升级时,应限制受影响服务的网络暴露面并部署访问控制措施。具体修复细节请以 Dell 官方安全公告为准。

原始情报

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Protection mechanism bypass, and Unauthorized access.