ZeroHour

CVE-2026-80238

large

Privilege Escalation to Root via Exposed Docker Socket in Dell Secure Connect Gateway 5.0

CVSS 3.1
9.3 critical
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-80238 is an execution-with-unnecessary-privileges flaw (CWE-250) in Dell Secure Connect Gateway (SCG) 5.0 in which an exposed Docker socket can be used to obtain host-level access without requiring a password, bypassing protection mechanisms. It is triggered by local access: a low-privileged operator with SSH access to the SCG host can leverage the exposed Docker socket to gain root-level access, and an attacker who has compromised a service running inside the orchestrator container can use the same socket to escape the container boundary and seize the host. Successful exploitation grants full root-level control of the gateway host, with high impact to confidentiality, integrity, and availability across the security scope (CVSS 3.1: 9.3, critical). Any organization running Dell SCG 5.0 Appliance versions prior to 5.36.00.16 or Dell SCG 5.0 Application versions prior to 5.36.00.00 is affected. No exploitation in the wild, public proof-of-concept, or KEV listing is known, and EPSS currently puts the 30-day exploitation probability at only 0.1% (4th percentile).

What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and Dell SCG 5.0 Application to version 5.36.00.00 or later at the earliest opportunity, per Dell's recommendation. Until upgraded, restrict low-privileged SSH/operator accounts on the gateway host, limit access to the exposed Docker socket, and monitor services inside the orchestrator container, treating any compromised container service as potential full host compromise. Because the flaw requires local access, there is no known remote exploitation path, but the container-escape vector means any attacker foothold in the orchestrator container yields host-level root control.

Affected
Dell Secure Connect Gateway (SCG) 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 Applicationprior to 5.36.00.00
Estimated exposure
large≈10,000–100,000 on-premises gateway deployments at enterprise customer sites (order-of-magnitude estimate) — No public install counts are available, so the estimate is based on deployment patterns: SCG is an on-premises support/connectivity gateway typically deployed once per enterprise customer site or datacenter, implying roughly tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is considered critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a password by leveraging the exposed Docker socket. Additionally, an attacker who compromises a service running within the orchestrator container can access the same socket and escape the container boundary to obtain host-level control. Dell recommends that customers upgrade at the earliest opportunity.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-250
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access

Dell patches three critical flaws (CVSS up to 9.8) in Secure Connect Gateway 5.0 enabling admin token replay, unauthenticated RCE, and root escalation.

Dell disclosed three critical vulnerabilities in Secure Connect Gateway 5.0 appliance and application deployments. CVE-2026-80172 (CVSS 9.8) lets unauthenticated attackers replay captured requests, which lack nonce validation and time limits, to repeatedly mint administrator access and refresh tokens. CVE-2026-61410 (9.4) is a missing-authorization flaw enabling unauthenticated remote command execution, and CVE-2026-80238 (9.3) is an exposed Docker socket allowing local privilege escalation to root and container escape. Fixes ship in appliance 5.36.00.16 and application 5.36.00.00.

Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access

Dell patched three critical Secure Connect Gateway flaws (CVE-2026-80172 up to CVSS 9.8) enabling unauthenticated admin access, remote code execution, and host takeover.

Dell Security Advisory DSA-2026-382 fixes three critical vulnerabilities in Secure Connect Gateway (SCG) 5.0, affecting appliances earlier than 5.36.00.16 and applications earlier than 5.36.00.00. CVE-2026-80172 (CVSS 9.8) allows unauthenticated replay of captured requests to obtain ADMIN access due to missing nonce and time validation; CVE-2026-61410 (9.4) enables unauthenticated command execution via missing authorization; CVE-2026-80238 (9.3) involves an exposed Docker socket allowing root access and container escape. Dell urges immediate upgrades and recommends restricting management interfaces to trusted networks and rotating credentials if compromise is suspected.