ZeroHour

CVE-2026-79689

large

Unauthenticated OS Command Injection in Dell Secure Connect Gateway 5.0

CVSS 3.1
9.8 critical
EPSS
2%p79
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0, in both Appliance and Application editions, contains an OS command injection flaw (CWE-78) in which special elements are not properly neutralized before being used in an operating system command. A remote, unauthenticated attacker who can reach the gateway over the network can send crafted input that the product fails to sanitize, leading to script injection on the host. The issue is rated critical (CVSS 9.8, AV:N/AC:L/PR:N) with high impact to confidentiality, integrity, and availability, indicating that successful exploitation could seriously compromise the gateway. Organizations running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00 are affected. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and no exploitation in the wild has been reported.

What to do: Upgrade SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later. Until patched, restrict network access to the gateway's interfaces with firewall rules or ACLs, prioritizing any gateways reachable from untrusted networks or the internet. Inventory deployments by checking the running version in the SCG administration interface, since the Application edition (software install) and Appliance edition (hardware/virtual appliance) have different fixed versions.

Affected
Dell Secure Connect Gateway 5.0 Applianceall versions prior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationall versions prior to 5.36.00.00
Estimated exposure
largetens of thousands of enterprise deployments (est.; ≈10k–100k sites, with only a subset remotely reachable by unauthenticated attackers) — SCG 5.0 is Dell's standard support-connectivity gateway deployed at organizations running Dell server and storage hardware under support contracts, so the install base plausibly tracks Dell's large enterprise footprint, though no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.