ZeroHour

CVE-2026-80135

large

Unauthenticated Protection Bypass in Dell Secure Connect Gateway 5.0

CVSS 3.1
5.3 medium
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-80135 is an improper check or handling of exceptional conditions (CWE-703) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the appliance and application editions. An unauthenticated attacker with network access to the gateway can trigger the flaw remotely, causing the product to mishandle an exceptional condition and bypass a protection mechanism; the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) scores the impact as high availability with no direct confidentiality or integrity loss. Affected users are organizations running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00, typically deployed to connect on-premises environments to Dell's connected support services. There is no evidence of exploitation in the wild, no CISA KEV listing, and no known public proof-of-concept; EPSS estimates only a 0.4% chance of exploitation in the next 30 days.

What to do: Upgrade Dell SCG 5.0 Appliance to 5.36.00.16 or later and Dell SCG 5.0 Application to 5.36.00.00 or later. In the interim, restrict network access to the gateway so only trusted management systems can reach it, and inventory both appliance and application deployments since they patch to different fixed versions. Check Dell's security advisory portal for any updates or additional affected components.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 Applicationprior to 5.36.00.00
Estimated exposure
largeon the order of tens of thousands of deployments worldwide, with only a subset internet-exposed — SCG is deployed roughly one-per-site as Dell's required connectivity gateway for enterprise connected-support/SupportAssist services, so the vulnerable pre-5.36.00.16/5.36.00.00 range plausibly spans tens of thousands of enterprise sites,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Check or Handling of Exceptional Conditions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-703
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.