CVE-2026-79963
largeCommand Execution via Unverified Code Download in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 contains a Download of Code Without Integrity Check flaw (CWE-494), meaning the product fetches code — such as update or support content — without verifying its integrity before use. An unauthenticated attacker with remote access could potentially exploit this to achieve command execution on the gateway, though the CVSS vector's high attack complexity (AC:H) indicates successful exploitation depends on non-trivial conditions. The measured impact is to integrity and availability (C:N/I:H/A:H), not confidentiality. Affected deployments are Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. There is currently no entry in CISA's KEV catalog and no public proof-of-concept or confirmed in-the-wild exploitation.
What to do: Upgrade Dell SCG 5.0 Appliance to 5.36.00.16 or later and Dell SCG 5.0 Application to 5.36.00.00 or later. In the meantime, restrict which hosts can reach the gateway remotely and review its outbound update/download paths for tampering. Because attack complexity is rated high and no public PoC exists, treat this as a patch-priority issue for internet-reachable or support-critical gateways rather than an emergency.
| Dell Secure Connect Gateway (SCG) 5.0 Appliance | All versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway (SCG) 5.0 Application | All versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-494
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.