CVE-2026-79695
largeUnauthenticated Data-Amplification DoS in Dell Secure Connect Gateway 5.0
CVE-2026-79695 is an Improper Handling of Highly Compressed Data (data amplification, CWE-409) flaw in Dell Secure Connect Gateway (SCG) 5.0, affecting the 5.0 Appliance in versions prior to 5.36.00.16 and the 5.0 Application in versions prior to 5.36.00.00. It is triggered when the gateway processes highly compressed input, allowing a small attacker-supplied request to expand into a disproportionately large amount of processing or memory consumption. An unauthenticated attacker with network access to the gateway could exploit this to exhaust resources and cause a denial of service; the CVSS 3.1 score is 7.3 High (AV:N/AC:L/PR:N/UI:N), with no privilege or user-interaction requirements. Only organizations running affected SCG 5.0 versions are exposed — typically enterprises that deploy the appliance or application to aggregate support telemetry from their Dell servers, storage, and networking hardware. There is currently no known exploitation in the wild, no public proof of concept, and the issue is not in the CISA KEV catalog.
What to do: Upgrade the SCG 5.0 Appliance to version 5.36.00.16 or later and the SCG 5.0 Application to version 5.36.00.00 or later. As an interim mitigation, restrict network access to the gateway's management interface so it is not reachable by unauthenticated remote users, and verify your running version via the appliance/application administration UI.
| Dell Secure Connect Gateway (SCG) 5.0 Appliance | all versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway (SCG) 5.0 Application | all versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-409
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.