ZeroHour

CVE-2026-80123

large

Unauthenticated SSRF in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.5 high
EPSS
<1%p8
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 contains a server-side request forgery vulnerability (CWE-918) in Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. An unauthenticated attacker with network reachability to the gateway can send crafted requests that cause the SCG service to issue attacker-controlled server-side requests. Per the CVSS scoring (C:N/I:N/A:H), the only impact claimed is denial of service, meaning the attacker can potentially disrupt or crash the gateway rather than read internal resources or alter data. Any organization running an affected SCG 5.0 Appliance or Application build is affected, though exploitability depends on the attacker being able to reach the gateway remotely. Exploitation status is unconfirmed: the flaw is not in CISA KEV and no public proof-of-concept is known.

What to do: Upgrade the SCG 5.0 Appliance to 5.36.00.16 or later and the SCG 5.0 Application to 5.36.00.00 or later per Dell's advisory. Until patched, restrict network access to the gateway's service interfaces and check whether your SCG instance is reachable from untrusted networks; watch for unexplained availability loss or restarts of the gateway service.

Affected
Dell Secure Connect Gateway 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationprior to 5.36.00.00
Estimated exposure
large≈ tens of thousands of gateway deployments (rough estimate from deployment patterns) — No public install counts exist for Dell SCG; the estimate assumes Dell's large enterprise customer base typically deploys one SCG gateway per site or managed environment, with only a fraction of those interfaces exposed to untrusted…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.