ZeroHour

CVE-2026-78490

large

Unauthenticated client-side request forgery in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-78490 is an improper restriction of excessive authentication attempts (CWE-307) in Dell Secure Connect Gateway (SCG) 5.0, meaning the software fails to limit or lock out repeated authentication attempts. An unauthenticated attacker with remote network access can trigger the flaw by sending excessive or crafted authentication requests to the gateway. Dell states that successful exploitation could lead to client-side request forgery, and the CVSS 3.1 vector rates the impact as high on confidentiality with no integrity or availability impact. Organizations running Dell SCG 5.0 Appliance versions prior to 5.36.00.16 or Dell SCG 5.0 Application versions prior to 5.36.00.00 are affected. There is currently no known exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog.

What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and Dell SCG 5.0 Application to version 5.36.00.00 or later, verifying deployed versions in the gateway's administration interface. Until patched, restrict access to the gateway's authentication interface to trusted management networks or VPN rather than exposing it directly to the internet, since the flaw is exploitable by unauthenticated remote attackers. Continue monitoring Dell security advisories, as no public PoC or in-the-wild exploitation is currently known.

Affected
Dell Secure Connect Gateway 5.0 Applianceall versions prior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationall versions prior to 5.36.00.00
Estimated exposure
largeon the order of tens of thousands of deployed gateways (typically one per customer site or datacenter); the internet-exposed share is unknown — Dell Secure Connect Gateway is deployed at customer environments that use Dell's connected-support services, generally one instance per site, so Dell's large enterprise install base plausibly implies a 10k-100k deployment footprint, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to client-side request forgery.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-307
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.