ZeroHour

CVE-2026-79692

Unauthenticated Filesystem Access via File Path Control in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.3 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-79692 is an External Control of File Name or Path vulnerability (CWE-73) in Dell Secure Connect Gateway (SCG) 5.0, affecting Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. Because the affected component accepts an attacker-controlled file name or path, an unauthenticated remote attacker can direct file operations to unintended locations on the target filesystem. Successful exploitation may allow the attacker to access, and potentially read or influence, files on the SCG Appliance or Application host. Any organization running Dell SCG 5.0 in the affected version ranges is exposed, with the Appliance and Application (software) deployment variants both impacted. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and the flaw is not listed in CISA's KEV catalog.

What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later, and SCG 5.0 Application to version 5.36.00.00 or later. In the interim, restrict network access to the SCG management interface to trusted administrative networks and verify the deployed variant (Appliance vs. Application) and running version. Monitor Dell's security advisory for updates, as no public PoC exists yet but exploitation may follow disclosure.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applianceall versions prior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 Applicationall versions prior to 5.36.00.00
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control of File Name or Path vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-73
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.