ZeroHour

CVE-2026-80133

Path Traversal Leading to RCE in Dell Secure Connect Gateway 5.0

CVSS 3.1
8.1 high
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-80133 is a relative path traversal flaw (CWE-23) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance and the Application editions. An unauthenticated attacker with remote network access could send crafted traversal input to the gateway, causing files or paths outside the intended directory to be reached and, per Dell's advisory, potentially resulting in remote code execution. A successful exploit gives the attacker code execution on the gateway host, with CVSS 3.1 scoring high confidentiality and integrity impact (7.4 High, network vector, high attack complexity, no privileges or user interaction required). Any organization running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00 is affected. There are no reports of exploitation in the wild, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS puts 30-day exploitation probability at about 0.5%.

What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and Dell SCG 5.0 Application to version 5.36.00.00 or later. Until patched, restrict network access to the gateway interface so only trusted management networks and Dell connectivity endpoints can reach it. Confirm deployed SCG editions and versions via your management console, and monitor Dell Security Advisories for updates.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applianceall versions prior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 Applicationall versions prior to 5.36.00.00
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-23
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.