ZeroHour

CVE-2026-80172

large

Unauthenticated Token Replay Flaw in Dell Secure Connect Gateway 5.0

CVSS 3.1
9.8 critical
EPSS
<1%p19
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 contains an Insufficient Verification of Data Authenticity flaw (CWE-345) that lets an unauthenticated remote attacker replay a previously captured request to obtain ADMIN access and refresh tokens. Because the product performs no nonce validation and imposes no time limit on requests, the same captured request can be reused indefinitely to mint new privileged tokens. An attacker gains persistent, unauthorized administrative access to the gateway, which serves as the connectivity hub between Dell customer environments and Dell support services. Organizations running SCG 5.0 Appliance prior to 5.36.00.16 or SCG 5.0 Application prior to 5.36.00.00 are affected. Exploitation has not been observed so far: EPSS puts 30-day exploitation probability at 0.3%, the flaw is not in CISA KEV, and no public proof-of-concept is known.

What to do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later as soon as possible. Until patched, restrict network access to the gateway's interface to trusted hosts and review recent authentication activity, since any captured request can be replayed indefinitely to obtain ADMIN tokens; consider rotating credentials and tokens if unauthorized access is suspected.

Affected
Dell Secure Connect Gateway (SCG) 5.0 ApplianceAll versions prior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 ApplicationAll versions prior to 5.36.00.00
Estimated exposure
largeon the order of tens of thousands of enterprise deployments worldwide — SCG is typically deployed as one appliance or application instance per enterprise environment to manage Dell hardware support connectivity, so the installed base scales with Dell's large enterprise support customer base rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could exploit this, leading to unauthorized access. This vulnerability is considered critical as an unauthenticated attacker can repeatedly reuse a captured request to generate ADMIN access and refresh tokens. Since there is no nonce validation or time limit on requests, the attack can be performed indefinitely. Dell recommends customers to upgrade at the earliest opportunity

Vendors
dell
Products
secure connect gateway
Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access

Dell patches three critical flaws (CVSS up to 9.8) in Secure Connect Gateway 5.0 enabling admin token replay, unauthenticated RCE, and root escalation.

Dell disclosed three critical vulnerabilities in Secure Connect Gateway 5.0 appliance and application deployments. CVE-2026-80172 (CVSS 9.8) lets unauthenticated attackers replay captured requests, which lack nonce validation and time limits, to repeatedly mint administrator access and refresh tokens. CVE-2026-61410 (9.4) is a missing-authorization flaw enabling unauthenticated remote command execution, and CVE-2026-80238 (9.3) is an exposed Docker socket allowing local privilege escalation to root and container escape. Fixes ship in appliance 5.36.00.16 and application 5.36.00.00.

Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access

Dell patched three critical Secure Connect Gateway flaws (CVE-2026-80172 up to CVSS 9.8) enabling unauthenticated admin access, remote code execution, and host takeover.

Dell Security Advisory DSA-2026-382 fixes three critical vulnerabilities in Secure Connect Gateway (SCG) 5.0, affecting appliances earlier than 5.36.00.16 and applications earlier than 5.36.00.00. CVE-2026-80172 (CVSS 9.8) allows unauthenticated replay of captured requests to obtain ADMIN access due to missing nonce and time validation; CVE-2026-61410 (9.4) enables unauthenticated command execution via missing authorization; CVE-2026-80238 (9.3) involves an exposed Docker socket allowing root access and container escape. Dell urges immediate upgrades and recommends restricting management interfaces to trusted networks and rotating credentials if compromise is suspected.