CVE-2026-80123
largeUnauthenticated SSRF in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 contains a server-side request forgery vulnerability (CWE-918) in Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. An unauthenticated attacker with network reachability to the gateway can send crafted requests that cause the SCG service to issue attacker-controlled server-side requests. Per the CVSS scoring (C:N/I:N/A:H), the only impact claimed is denial of service, meaning the attacker can potentially disrupt or crash the gateway rather than read internal resources or alter data. Any organization running an affected SCG 5.0 Appliance or Application build is affected, though exploitability depends on the attacker being able to reach the gateway remotely. Exploitation status is unconfirmed: the flaw is not in CISA KEV and no public proof-of-concept is known.
What to do: Upgrade the SCG 5.0 Appliance to 5.36.00.16 or later and the SCG 5.0 Application to 5.36.00.00 or later per Dell's advisory. Until patched, restrict network access to the gateway's service interfaces and check whether your SCG instance is reachable from untrusted networks; watch for unexplained availability loss or restarts of the gateway service.
| Dell Secure Connect Gateway 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.