ZeroHour

CVE-2026-78493

large

OS command injection in Dell Secure Connect Gateway 5.0 allows local command execution

CVSS 3.1
7.8 high
EPSS
2%p77
Published
()
Modified
AI analysis

CVE-2026-78493 is an OS command injection flaw (CWE-77) in Dell Secure Connect Gateway 5.0, where the software fails to properly neutralize special shell characters before passing input to the operating system. A low-privileged attacker with local access to the gateway can submit crafted input containing shell metacharacters, causing arbitrary OS commands to be executed. Successful exploitation yields command execution on the appliance or application host, with confidentiality, integrity and availability all rated highly impacted (CVSS 3.1 7.8, AV:L/AC:L/PR:L/UI:N/S:U). It affects organizations running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00; these gateways are typically deployed in enterprise environments to broker support and telemetry connectivity with Dell. No exploitation has been reported: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later, or SCG 5.0 Application to version 5.36.00.00 or later. Because exploitation requires low-privileged local access, restrict local and management-interface access on the SCG host to trusted administrators and audit low-privileged local accounts. Check the deployed version in the SCG administration console to determine whether the fix is needed.

Affected
Dell Secure Connect Gateway 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationprior to 5.36.00.00
Estimated exposure
largeon the order of 10,000-100,000 vulnerable gateway/application deployments (tens of thousands; clearly an estimate) — Secure Connect Gateway is deployed as a site-level support-connectivity appliance or application across Dell's large enterprise install base, which plausibly puts vulnerable SCG 5.0 instances in the tens of thousands, though no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-77
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.