ZeroHour

CVE-2026-79645

large

Unauthenticated Access in Dell Secure Connect Gateway (SCG) 5.0

CVSS 3.1
8.2 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-79645 is a missing authentication for critical function flaw (CWE-306) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance and Application editions. An unauthenticated attacker with remote network access to the affected SCG service can invoke a critical function without logging in, resulting in unauthorized access. The CVSS 3.1 score of 8.2 reflects network reachability, low attack complexity, no required privileges or user interaction, a low confidentiality impact, and a high integrity impact. Organizations running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00 are affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates only about a 0.2% chance of exploitation within the next 30 days.

What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later. Until patched, restrict network access to the SCG service with firewall/ACL rules or VPN-only access and avoid exposing it to the internet. Inventory deployed SCG versions via the admin console and monitor Dell's security advisory for updates and additional guidance.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 Applicationprior to 5.36.00.00
Estimated exposure
largeon the order of tens of thousands of gateway deployments worldwide (estimated; no public install-base, plugin, or internet-scan counts available) — Dell SCG 5.0 is typically deployed once per enterprise environment to connect Dell infrastructure to Dell support services, so the order of magnitude is inferred from Dell's large enterprise customer base rather than any public scan or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.