ZeroHour

CVE-2026-79695

large

Unauthenticated Data-Amplification DoS in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.3 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-79695 is an Improper Handling of Highly Compressed Data (data amplification, CWE-409) flaw in Dell Secure Connect Gateway (SCG) 5.0, affecting the 5.0 Appliance in versions prior to 5.36.00.16 and the 5.0 Application in versions prior to 5.36.00.00. It is triggered when the gateway processes highly compressed input, allowing a small attacker-supplied request to expand into a disproportionately large amount of processing or memory consumption. An unauthenticated attacker with network access to the gateway could exploit this to exhaust resources and cause a denial of service; the CVSS 3.1 score is 7.3 High (AV:N/AC:L/PR:N/UI:N), with no privilege or user-interaction requirements. Only organizations running affected SCG 5.0 versions are exposed — typically enterprises that deploy the appliance or application to aggregate support telemetry from their Dell servers, storage, and networking hardware. There is currently no known exploitation in the wild, no public proof of concept, and the issue is not in the CISA KEV catalog.

What to do: Upgrade the SCG 5.0 Appliance to version 5.36.00.16 or later and the SCG 5.0 Application to version 5.36.00.00 or later. As an interim mitigation, restrict network access to the gateway's management interface so it is not reachable by unauthenticated remote users, and verify your running version via the appliance/application administration UI.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applianceall versions prior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 Applicationall versions prior to 5.36.00.00
Estimated exposure
largeplausibly on the order of tens of thousands of on-premises SCG 5.0 deployments worldwide (estimate; no official install counts published) — Dell Secure Connect Gateway is deployed per enterprise customer site/network to consolidate support connections for Dell hardware, so given the size of Dell's enterprise install base the number of SCG 5.0 deployments is plausibly in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-409
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.