CVE-2026-79641
—OS Command Injection Privilege Escalation in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 contains an OS command injection flaw (CWE-78) in which special elements are improperly neutralized before being passed to the operating system. A remote attacker who already holds low-privileged access to the SCG Appliance or Application can trigger the flaw, and because it is a command injection the attacker can execute OS commands beyond their intended scope. The practical outcome is elevation of privileges on the affected system, with high impact to confidentiality, integrity, and availability as reflected in the 7.5 (high) CVSS 3.1 score. The flaw affects both the SCG 5.0 Appliance (versions prior to 5.36.00.16) and the SCG 5.0 Application (versions prior to 5.36.00.00). There is currently no CISA KEV listing, no public proof-of-concept, and no known exploitation in the wild.
What to do: Upgrade SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later, per Dell's advisory. As interim mitigation, limit remote access to the gateway and minimize low-privileged accounts on it, since exploitation requires existing low-privileged access. Inventory your environment for SCG 5.0 Appliance and Application deployments and verify the running version before patching.
| Dell Secure Connect Gateway 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.