CVE-2026-80127
largeOS Command Injection in Dell Secure Connect Gateway 5.0 Appliance and Application
Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application contain an OS command injection flaw (CWE-78) in which special elements are not properly neutralized before being passed to the operating system. A remote attacker who already holds high-privileged access to the SCG management interface can trigger the flaw by injecting commands into that interface, which are then executed on the underlying host. Successful exploitation breaks the attacker out of the application context into OS-level execution, yielding elevation of privileges with high impact on confidentiality, integrity, and availability (CVSS 3.1 7.2, AV:N/AC:L/PR:H). Organizations running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00 are affected. Exploitation has not been confirmed: there is no entry in CISA's Known Exploited Vulnerabilities catalog, no known public proof-of-concept, and EPSS currently assigns a modest 0.9% probability of exploitation within 30 days.
What to do: Upgrade SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later. Because exploitation requires high-privileged credentials, restrict the management interface to trusted administrative networks, minimize the number of admin accounts, and audit local accounts on exposed gateways. Review appliance logs for unexpected command execution or unfamiliar administrative activity until the upgrade is complete.
| Dell Secure Connect Gateway (SCG) 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway (SCG) 5.0 Application | prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.