ZeroHour

CVE-2026-61409

large

Unauthenticated OS Command Injection in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.3 high
EPSS
1%p70
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 Application versions prior to 5.36.00.00 contain an OS command injection flaw (CWE-78) in which special elements in attacker-controlled input are not properly neutralized before being passed to the operating system. Because the flaw is reachable over the network without authentication, an unauthenticated remote attacker who can reach the gateway's interface could submit crafted input that is executed as an OS command. Successful exploitation results in remote command execution on the system running the SCG application, with the CVSS vector indicating a limited-but-real impact on confidentiality, integrity, and availability. Only organizations running the SCG 5.0 Application (the enterprise virtual-appliance edition of Dell's secure remote connectivity software) on affected versions are exposed. There are currently no reports of exploitation in the wild and no known public proof-of-concept; EPSS estimates about a 1.4% probability of exploitation within the next 30 days.

What to do: Upgrade the SCG 5.0 Application to version 5.36.00.00 or later per Dell's advisory. Until patched, restrict network access to the gateway's service and management interfaces to trusted management networks and confirm no SCG instance is exposed to untrusted networks or the internet. Inventory Dell management appliances in your environment to identify any running the 5.0 Application and verify their installed version.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applicationall versions prior to 5.36.00.00
Estimated exposure
largelikely on the order of tens of thousands of enterprise deployments worldwide, most of them deployed internally rather than directly internet-exposed — No public install counts or scan data are available, so this is an order-of-magnitude guess based on deployment patterns: SCG 5.0 is the virtual-appliance edition of Dell's secure remote support connectivity, typically deployed per…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.