ZeroHour

CVE-2026-80129

large

Unauthenticated Path Traversal RCE in Dell Secure Connect Gateway 5.0

CVSS 3.1
9.8 critical
EPSS
<1%p36
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 contains an improper limitation of a pathname to a restricted directory (CWE-22, path traversal) vulnerability in both its Appliance and Application forms. An unauthenticated attacker with network access to the gateway can send crafted path input that escapes the intended directory restriction, which can lead to remote execution of attacker-controlled code on the host. Successful exploitation carries critical impact (CVSS 3.1: 9.8, network vector, no privileges or user interaction required, high confidentiality/integrity/availability impact). Affected deployments are SCG 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later. Because the flaw is remotely exploitable without authentication, also check whether any SCG instances are reachable from untrusted networks and restrict access to the gateway's management/service interfaces until patched.

Affected
Dell Secure Connect Gateway 5.0 Applianceall versions prior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationall versions prior to 5.36.00.00
Estimated exposure
large≈10,000–100,000 SCG installations worldwide (exact install base unpublished; internet-exposed subset likely far smaller) — Secure Connect Gateway is Dell's standard enterprise support-connectivity gateway, typically deployed once or a few times per customer datacenter/site, so the plausible install base is on the order of tens of thousands of enterprise…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.