ZeroHour
Product

Secure Connect Gateway

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access

Dell patches three critical flaws (CVSS up to 9.8) in Secure Connect Gateway 5.0 enabling admin token replay, unauthenticated RCE, and root escalation.

Dell disclosed three critical vulnerabilities in Secure Connect Gateway 5.0 appliance and application deployments. CVE-2026-80172 (CVSS 9.8) lets unauthenticated attackers replay captured requests, which lack nonce validation and time limits, to repeatedly mint administrator access and refresh tokens. CVE-2026-61410 (9.4) is a missing-authorization flaw enabling unauthenticated remote command execution, and CVE-2026-80238 (9.3) is an exposed Docker socket allowing local privilege escalation to root and container escape. Fixes ship in appliance 5.36.00.16 and application 5.36.00.00.

Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access

Dell patched three critical Secure Connect Gateway flaws (CVE-2026-80172 up to CVSS 9.8) enabling unauthenticated admin access, remote code execution, and host takeover.

Dell Security Advisory DSA-2026-382 fixes three critical vulnerabilities in Secure Connect Gateway (SCG) 5.0, affecting appliances earlier than 5.36.00.16 and applications earlier than 5.36.00.00. CVE-2026-80172 (CVSS 9.8) allows unauthenticated replay of captured requests to obtain ADMIN access due to missing nonce and time validation; CVE-2026-61410 (9.4) enables unauthenticated command execution via missing authorization; CVE-2026-80238 (9.3) involves an exposed Docker socket allowing root access and container escape. Dell urges immediate upgrades and recommends restricting management interfaces to trusted networks and rotating credentials if compromise is suspected.

Related CVEs

  • Unauthenticated Token Replay Flaw in Dell Secure Connect Gateway 5.0
    Dell Secure Connect Gateway (SCG) 5.0 contains an Insufficient Verification of Data Authenticity flaw (CWE-345) that lets an unauthenticated remote attacker replay a previously captured request to obtain ADMIN access and refresh tokens. Because the product performs no nonce validation and imposes no time limit on requests, the same captured request can be reused indefinitely to mint new privileged tokens. An attacker gains persistent, unauthorized administrative access to the gateway, which serves as the connectivity hub between Dell customer environments and Dell support services. Organizations running SCG 5.0 Appliance prior to 5.36.00.16 or SCG 5.0 Application prior to 5.36.00.00 are affected. Exploitation has not been observed so far: EPSS puts 30-day exploitation probability at 0.3%, the flaw is not in CISA KEV, and no public proof-of-concept is known.
    · Dell Secure Connect Gateway (SCG) 5.0 Appliance All versions prior to 5.36.00.16 · Dell Secure Connect Gateway (SCG) 5.0 Application All versions prior to 5.36.00.00large
  • Missing Authorization Allows Unauthenticated RCE in Dell Secure Connect Gateway 5.0
    CVE-2026-61410 is a missing-authorization flaw (CWE-862) in Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00. An unauthenticated attacker with remote network access can send specially crafted requests that bypass the application's intended restrictions on code execution, triggering remote command execution on the gateway host. Given the CVSS 9.4 vector (high confidentiality and integrity impact, low availability impact), a successful attacker effectively gains broad control over the system, and related reporting also describes unauthenticated RCE and admin access on affected SCG deployments. Any organization running the affected SCG 5.x builds — typically enterprises using SCG as the on-premises gateway that connects Dell EMC infrastructure to Dell support services — is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates a modest 1.3% probability of exploitation within 30 days.
    · Dell Secure Connect Gateway (SCG) 5.0 Appliance all versions prior to 5.36.00.16 · Dell Secure Connect Gateway (SCG) 5.0 Application all versions prior to 5.36.00.00large
  • Privilege Escalation to Root via Exposed Docker Socket in Dell Secure Connect Gateway 5.0
    CVE-2026-80238 is an execution-with-unnecessary-privileges flaw (CWE-250) in Dell Secure Connect Gateway (SCG) 5.0 in which an exposed Docker socket can be used to obtain host-level access without requiring a password, bypassing protection mechanisms. It is triggered by local access: a low-privileged operator with SSH access to the SCG host can leverage the exposed Docker socket to gain root-level access, and an attacker who has compromised a service running inside the orchestrator container can use the same socket to escape the container boundary and seize the host. Successful exploitation grants full root-level control of the gateway host, with high impact to confidentiality, integrity, and availability across the security scope (CVSS 3.1: 9.3, critical). Any organization running Dell SCG 5.0 Appliance versions prior to 5.36.00.16 or Dell SCG 5.0 Application versions prior to 5.36.00.00 is affected. No exploitation in the wild, public proof-of-concept, or KEV listing is known, and EPSS currently puts the 30-day exploitation probability at only 0.1% (4th percentile).
    · Dell Secure Connect Gateway (SCG) 5.0 Appliance prior to 5.36.00.16 · Dell Secure Connect Gateway (SCG) 5.0 Application prior to 5.36.00.00large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.