ZeroHour

CVE-2026-79963

large

Command Execution via Unverified Code Download in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 contains a Download of Code Without Integrity Check flaw (CWE-494), meaning the product fetches code — such as update or support content — without verifying its integrity before use. An unauthenticated attacker with remote access could potentially exploit this to achieve command execution on the gateway, though the CVSS vector's high attack complexity (AC:H) indicates successful exploitation depends on non-trivial conditions. The measured impact is to integrity and availability (C:N/I:H/A:H), not confidentiality. Affected deployments are Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. There is currently no entry in CISA's KEV catalog and no public proof-of-concept or confirmed in-the-wild exploitation.

What to do: Upgrade Dell SCG 5.0 Appliance to 5.36.00.16 or later and Dell SCG 5.0 Application to 5.36.00.00 or later. In the meantime, restrict which hosts can reach the gateway remotely and review its outbound update/download paths for tampering. Because attack complexity is rated high and no public PoC exists, treat this as a patch-priority issue for internet-reachable or support-critical gateways rather than an emergency.

Affected
Dell Secure Connect Gateway (SCG) 5.0 ApplianceAll versions prior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 ApplicationAll versions prior to 5.36.00.00
Estimated exposure
largeon the order of tens of thousands of enterprise gateway deployments (estimate) — SCG is Dell's standard support/telemetry gateway deployed across a large share of its enterprise infrastructure customer base, so deployment patterns suggest a five-figure install base, though few instances are directly internet-exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-494
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.