CVE-2026-79643
largeIncorrect Operator in Dell Secure Connect Gateway 5.0 Allows Unauthenticated Access
Dell Secure Connect Gateway (SCG) 5.0 contains a 'use of incorrect operator' flaw (CWE-480), a coding logic error in which the wrong operator is used in a check, causing access controls to be applied incorrectly. It is exploitable remotely over the network with no authentication and no user interaction (CVSS vector AV:N/AC:L/PR:N/UI:N) by sending crafted requests to an affected SCG 5.0 Appliance or SCG 5.0 Application. A successful attacker gains unauthorized access to the gateway, with confidentiality, integrity, and availability impacts each rated low (CVSS 7.3, High). At-risk organizations are those running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00. No exploitation is currently known: the issue is absent from CISA's KEV catalog, no public proof-of-concept is known, and EPSS estimates only about a 0.3% chance of exploitation within 30 days.
What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and Dell SCG 5.0 Application to version 5.36.00.00 or later. Until patched, restrict network access to the gateway's management/API interfaces to trusted management networks and review access logs for unexpected unauthenticated connections. Inventory deployed SCG versions via the SCG interface or Dell's support tooling to identify which sites require remediation.
| Dell Secure Connect Gateway (SCG) 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway (SCG) 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Incorrect Operator vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-480
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.