CVE-2026-61409
largeUnauthenticated OS Command Injection in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 Application versions prior to 5.36.00.00 contain an OS command injection flaw (CWE-78) in which special elements in attacker-controlled input are not properly neutralized before being passed to the operating system. Because the flaw is reachable over the network without authentication, an unauthenticated remote attacker who can reach the gateway's interface could submit crafted input that is executed as an OS command. Successful exploitation results in remote command execution on the system running the SCG application, with the CVSS vector indicating a limited-but-real impact on confidentiality, integrity, and availability. Only organizations running the SCG 5.0 Application (the enterprise virtual-appliance edition of Dell's secure remote connectivity software) on affected versions are exposed. There are currently no reports of exploitation in the wild and no known public proof-of-concept; EPSS estimates about a 1.4% probability of exploitation within the next 30 days.
What to do: Upgrade the SCG 5.0 Application to version 5.36.00.00 or later per Dell's advisory. Until patched, restrict network access to the gateway's service and management interfaces to trusted management networks and confirm no SCG instance is exposed to untrusted networks or the internet. Inventory Dell management appliances in your environment to identify any running the 5.0 Application and verify their installed version.
| Dell Secure Connect Gateway (SCG) 5.0 Application | all versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.