CVE-2026-78480
largeMissing Authentication in Dell Secure Connect Gateway 5.0 Appliance and Application
CVE-2026-78480 is a missing authentication for critical function flaw (CWE-306) in Dell Secure Connect Gateway (SCG) 5.0, affecting the Appliance prior to version 5.36.00.16 and the Application prior to version 5.36.00.00. An unauthenticated attacker with network access to the gateway can invoke critical functions that lack authentication checks, gaining unauthorized access; the published CVSS 3.1 vector (7.5, network vector, no privileges or user interaction required) scores the impact as availability-high with no direct confidentiality or integrity impact. Affected organizations are those running SCG 5.0, which is typically deployed as a virtual appliance or software gateway inside enterprise networks to provide connectivity between Dell infrastructure and Dell's support backend. There is currently no evidence of exploitation: the flaw is not in CISA's KEV catalog, has no known public proof-of-concept, and EPSS assigns it a low 0.3% probability of exploitation within 30 days.
What to do: Upgrade the SCG 5.0 Appliance to version 5.36.00.16 or later and the SCG 5.0 Application to version 5.36.00.00 or later. Until patched, restrict network access to the gateway so only management networks and required Dell connectivity endpoints can reach it, and inventory deployments to identify any SCG instances exposed to untrusted networks.
| Dell Secure Connect Gateway (SCG) 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway (SCG) 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.