ZeroHour

CVE-2026-79635

Unauthenticated SSRF in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.3 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-79635 is a Server-Side Request Forgery (SSRF) flaw (CWE-918) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance edition and the Application edition. An unauthenticated attacker with network access to the SCG can trigger the gateway to make forged requests, potentially leading to unauthorized access to internal resources reachable from the gateway. The CVSS 3.1 base score is 7.3 (High) with network attack vector, low attack complexity, and no privileges or user interaction required, with low impacts to confidentiality, integrity, and availability. Any organization running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00 is affected. No public proof-of-concept, known exploited-vulnerability listing, or reported in-the-wild exploitation is currently known.

What to do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later. In the meantime, restrict which clients can reach the SCG management interface and limit the gateway's outbound network access to required Dell endpoints. Inventory your environment for both appliance and application deployments, as both editions are separately affected.

Affected
Dell Secure Connect Gateway 5.0 ApplianceAll versions prior to 5.36.00.16
Dell Secure Connect Gateway 5.0 ApplicationAll versions prior to 5.36.00.00
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.