ZeroHour

Vulnerabilities

1,662 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-79689
Unauthenticated OS Command Injection in Dell Secure Connect Gateway 5.0

Dell Secure Connect Gateway (SCG) 5.0, in both Appliance and Application editions, contains an OS command injection flaw (CWE-78) in which special elements are not properly neutralized before being used in an operating system command. A remote, unauthenticated attacker who can reach the gateway over the network can send crafted input that the product fails to sanitize, leading to script injection on the host. The issue is rated critical (CVSS 9.8, AV:N/AC:L/PR:N) with high impact to confidentiality, integrity, and availability, indicating that successful exploitation could seriously compromise the gateway. Organizations running SCG 5.0 Appliance versions prior to 5.36.00.16 or SCG 5.0 Application versions prior to 5.36.00.00 are affected. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and no exploitation in the wild has been reported.

Do: Upgrade SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later. Until patched, restrict network access to the gateway's interfaces with firewall rules or ACLs, prioritizing any gateways reachable from untrusted networks or the internet. Inventory deployments by checking the running version in the SCG administration interface, since the Application edition (software install) and Appliance edition (hardware/virtual appliance) have different fixed versions.

9.8
group max
2%
  • Dell Secure Connect Gateway 5.0 Appliance all versions prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application all versions prior to 5.36.00.00
largetens of thousands of enterprise deployments (est.; ≈10k–100k sites, with only a subset remotely reachable by unauthenticated attackers)