ZeroHour

CVE-2026-78485

large

Unauthenticated Path Traversal in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.3 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-78485 is a path traversal flaw (CWE-22) in Dell Secure Connect Gateway 5.0, where user-controlled path input is not properly restricted to an allowed directory. A remote attacker with no credentials or user interaction can send crafted path-based requests to the gateway, causing file or resource access outside the intended restricted directory. Successful exploitation may lead to unauthorized access to sensitive data or gateway functionality (CVSS v3.1 7.3 high, with modest confidentiality, integrity, and availability impact per the vector). Affected deployments are Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Upgrade Dell SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later. Until patched, restrict network access to the gateway's management interface (firewall/ACLs, VPN-only access) and review gateway access logs for unexpected remote requests. Since no public PoC exists, prioritize internet-facing or otherwise remotely reachable SCG deployments for remediation.

Affected
Dell Secure Connect Gateway 5.0 Applianceall versions prior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationall versions prior to 5.36.00.00
Estimated exposure
large≈10k–100k deployed SCG 5.0 instances, with only a subset internet-exposed — Secure Connect Gateway is Dell's standard support-connectivity component widely deployed at customer sites running Dell infrastructure, so the install base likely reaches tens of thousands, though many gateways sit on internal networks…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access

Vendors
dell
Products
secure connect gateway
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.