ZeroHour

CVE-2026-79643

large

Incorrect Operator in Dell Secure Connect Gateway 5.0 Allows Unauthenticated Access

CVSS 3.1
7.3 high
EPSS
<1%p17
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 contains a 'use of incorrect operator' flaw (CWE-480), a coding logic error in which the wrong operator is used in a check, causing access controls to be applied incorrectly. It is exploitable remotely over the network with no authentication and no user interaction (CVSS vector AV:N/AC:L/PR:N/UI:N) by sending crafted requests to an affected SCG 5.0 Appliance or SCG 5.0 Application. A successful attacker gains unauthorized access to the gateway, with confidentiality, integrity, and availability impacts each rated low (CVSS 7.3, High). At-risk organizations are those running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00. No exploitation is currently known: the issue is absent from CISA's KEV catalog, no public proof-of-concept is known, and EPSS estimates only about a 0.3% chance of exploitation within 30 days.

What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and Dell SCG 5.0 Application to version 5.36.00.00 or later. Until patched, restrict network access to the gateway's management/API interfaces to trusted management networks and review access logs for unexpected unauthenticated connections. Inventory deployed SCG versions via the SCG interface or Dell's support tooling to identify which sites require remediation.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 Applicationprior to 5.36.00.00
Estimated exposure
largelikely tens of thousands of SCG 5.0 appliance/application deployments worldwide (no published install counts) — Dell distributes SCG 5.0 as the per-site remote-support gateway used by enterprise customers for SupportAssist connectivity, so with no public install-base figures or internet-scan counts this is an order-of-magnitude estimate based on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Incorrect Operator vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-480
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.