CVE-2026-80129
largeUnauthenticated Path Traversal RCE in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 contains an improper limitation of a pathname to a restricted directory (CWE-22, path traversal) vulnerability in both its Appliance and Application forms. An unauthenticated attacker with network access to the gateway can send crafted path input that escapes the intended directory restriction, which can lead to remote execution of attacker-controlled code on the host. Successful exploitation carries critical impact (CVSS 3.1: 9.8, network vector, no privileges or user interaction required, high confidentiality/integrity/availability impact). Affected deployments are SCG 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later. Because the flaw is remotely exploitable without authentication, also check whether any SCG instances are reachable from untrusted networks and restrict access to the gateway's management/service interfaces until patched.
| Dell Secure Connect Gateway 5.0 Appliance | all versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | all versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.