Privilege Escalation to Root via Exposed Docker Socket in Dell Secure Connect Gateway 5.0
AI analysis
CVE-2026-80238 is an execution-with-unnecessary-privileges flaw (CWE-250) in Dell Secure Connect Gateway (SCG) 5.0 in which an exposed Docker socket can be used to obtain host-level access without requiring a password, bypassing protection mechanisms. It is triggered by local access: a low-privileged operator with SSH access to the SCG host can leverage the exposed Docker socket to gain root-level access, and an attacker who has compromised a service running inside the orchestrator container can use the same socket to escape the container boundary and seize the host. Successful exploitation grants full root-level control of the gateway host, with high impact to confidentiality, integrity, and availability across the security scope (CVSS 3.1: 9.3, critical). Any organization running Dell SCG 5.0 Appliance versions prior to 5.36.00.16 or Dell SCG 5.0 Application versions prior to 5.36.00.00 is affected. No exploitation in the wild, public proof-of-concept, or KEV listing is known, and EPSS currently puts the 30-day exploitation probability at only 0.1% (4th percentile).
What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and Dell SCG 5.0 Application to version 5.36.00.00 or later at the earliest opportunity, per Dell's recommendation. Until upgraded, restrict low-privileged SSH/operator accounts on the gateway host, limit access to the exposed Docker socket, and monitor services inside the orchestrator container, treating any compromised container service as potential full host compromise. Because the flaw requires local access, there is no known remote exploitation path, but the container-escape vector means any attacker foothold in the orchestrator container yields host-level root control.
Affected
| Dell Secure Connect Gateway (SCG) 5.0 Appliance | prior to 5.36.00.16 |
| Dell Secure Connect Gateway (SCG) 5.0 Application | prior to 5.36.00.00 |
Estimated exposure
large≈10,000–100,000 on-premises gateway deployments at enterprise customer sites (order-of-magnitude estimate) — No public install counts are available, so the estimate is based on deployment patterns: SCG is an on-premises support/connectivity gateway typically deployed once per enterprise customer site or datacenter, implying roughly tens of…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is considered critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a password by leveraging the exposed Docker socket. Additionally, an attacker who compromises a service running within the orchestrator container can access the same socket and escape the container boundary to obtain host-level control. Dell recommends that customers upgrade at the earliest opportunity.