ZeroHour

CVE-2026-80132

large

Missing Authentication in Dell Secure Connect Gateway 5.0

CVSS 3.1
8.1 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-80132 is a missing authentication flaw (CWE-306) in Dell Secure Connect Gateway (SCG) 5.0, affecting the Appliance prior to version 5.36.00.16 and the Application prior to version 5.36.00.00. Because a critical function lacks authentication, an unauthenticated attacker with remote network access to the gateway can trigger the flaw without any credentials or user interaction. Per the CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), successful exploitation can lead to unauthorized access with potentially high impact on confidentiality, integrity, and availability, though the high attack-complexity score suggests exploitation is not straightforward. Organizations running SCG 5.0 to broker secure support connectivity for Dell products are affected until they patch. As of now there is no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days (28th percentile).

What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later. In the interim, restrict network access to the gateway so only trusted management networks and required Dell connectivity endpoints can reach it, and verify deployed versions via the appliance/application administration interface. Continue monitoring Dell's security advisory for updates, since exploitation status may change.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applianceall versions prior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 Applicationall versions prior to 5.36.00.00
Estimated exposure
largeplausibly on the order of tens of thousands of gateway deployments worldwide, with only a subset directly internet-exposed — SCG is deployed one or a few times per enterprise environment to provide SupportAssist connectivity across Dell's very large enterprise install base, so the vulnerable 5.0 series plausibly has tens of thousands of installations, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.