CVE-2026-79645
largeUnauthenticated Access in Dell Secure Connect Gateway (SCG) 5.0
CVE-2026-79645 is a missing authentication for critical function flaw (CWE-306) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance and Application editions. An unauthenticated attacker with remote network access to the affected SCG service can invoke a critical function without logging in, resulting in unauthorized access. The CVSS 3.1 score of 8.2 reflects network reachability, low attack complexity, no required privileges or user interaction, a low confidentiality impact, and a high integrity impact. Organizations running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00 are affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates only about a 0.2% chance of exploitation within the next 30 days.
What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later. Until patched, restrict network access to the SCG service with firewall/ACL rules or VPN-only access and avoid exposing it to the internet. Inventory deployed SCG versions via the admin console and monitor Dell's security advisory for updates and additional guidance.
| Dell Secure Connect Gateway (SCG) 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway (SCG) 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.