ZeroHour

CVE-2026-79941

large

Unauthenticated Command Injection in Dell Secure Connect Gateway 5.0

CVSS 3.1
9.8 critical
EPSS
2%p79
Published
()
Modified
AI analysis

CVE-2026-79941 is a critical command injection flaw (CWE-77) in Dell Secure Connect Gateway 5.0, affecting both the Appliance edition and the Application edition. An unauthenticated attacker with remote access can send input containing special characters that the gateway fails to neutralize before it is used in a command, which Dell describes as leading to script injection. Successful exploitation could allow the attacker to execute injected commands or scripts on the gateway host, with CVSS 3.1 scoring high impact to confidentiality, integrity, and availability (9.8 Critical). Affected organizations are those running SCG 5.0 Appliance or Application versions prior to the fixed releases, typically enterprises that use the gateway to connect Dell servers, storage, and other infrastructure to Dell support services. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and no exploitation is known.

What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later. Because the flaw is exploitable by unauthenticated remote attackers at Critical severity, restrict network access to the gateway (it should not be broadly internet-exposed) and review gateway logs for unexpected commands or scripts. Monitor the Dell security advisory for updates, as no public PoC exists yet but exploitability is likely given the unauthenticated network vector.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applianceversions prior to 5.36.00.16 (fixed in 5.36.00.16)
Dell Secure Connect Gateway (SCG) 5.0 Applicationversions prior to 5.36.00.00 (fixed in 5.36.00.00)
Estimated exposure
largelikely on the order of tens of thousands of enterprise gateway deployments worldwide (no public install or internet-exposure counts available) — No install counts or public scan data are available, so this is inferred from deployment patterns: SCG 5.0 is deployed as a per-organization or per-site connectivity appliance/application at enterprises running Dell hardware, implying at…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.