CVE-2026-78484
largeLocal OS Command Injection in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 Appliance and SCG 5.0 Application contain an OS command injection flaw (CWE-77) in which special elements are improperly neutralized, allowing injected operating-system commands to run. A low-privileged attacker with local access to the appliance or the host running the application can trigger the flaw without user interaction and gain command execution, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 7.8). Because the attack vector is local (AV:L), remote network exploitation is not possible, but any compromised low-privileged local account or process on the gateway could escalate to full command execution. Users running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00 are affected. There is currently no known exploitation in the wild, the flaw is not listed in CISA's KEV catalog, and no public proof-of-concept is available.
What to do: Upgrade Dell SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later per Dell's security advisory (CNA: Dell EMC). Until patched, restrict local console/SSH access on the gateway to trusted administrators and review the local accounts on the appliance and application host. Check your deployed SCG version in the management interface to confirm whether you fall within the affected ranges.
| Dell Secure Connect Gateway 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.