ZeroHour

CVE-2026-78480

large

Missing Authentication in Dell Secure Connect Gateway 5.0 Appliance and Application

CVSS 3.1
7.5 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-78480 is a missing authentication for critical function flaw (CWE-306) in Dell Secure Connect Gateway (SCG) 5.0, affecting the Appliance prior to version 5.36.00.16 and the Application prior to version 5.36.00.00. An unauthenticated attacker with network access to the gateway can invoke critical functions that lack authentication checks, gaining unauthorized access; the published CVSS 3.1 vector (7.5, network vector, no privileges or user interaction required) scores the impact as availability-high with no direct confidentiality or integrity impact. Affected organizations are those running SCG 5.0, which is typically deployed as a virtual appliance or software gateway inside enterprise networks to provide connectivity between Dell infrastructure and Dell's support backend. There is currently no evidence of exploitation: the flaw is not in CISA's KEV catalog, has no known public proof-of-concept, and EPSS assigns it a low 0.3% probability of exploitation within 30 days.

What to do: Upgrade the SCG 5.0 Appliance to version 5.36.00.16 or later and the SCG 5.0 Application to version 5.36.00.00 or later. Until patched, restrict network access to the gateway so only management networks and required Dell connectivity endpoints can reach it, and inventory deployments to identify any SCG instances exposed to untrusted networks.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 Applicationprior to 5.36.00.00
Estimated exposure
largelikely tens of thousands of enterprise deployments worldwide (order of magnitude 10,000-100,000 gateways); the internet-exposed subset is unknown — Dell SCG 5.0 is a remote-support gateway generally deployed one-per-customer-site by enterprises using Dell support connectivity, suggesting an install base in the tens of thousands of sites, but no public install counts or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.