Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access
Dell patches three critical flaws (CVSS up to 9.8) in Secure Connect Gateway 5.0 enabling admin token replay, unauthenticated RCE, and root escalation.
Dell disclosed three critical vulnerabilities in Secure Connect Gateway 5.0 appliance and application deployments. CVE-2026-80172 (CVSS 9.8) lets unauthenticated attackers replay captured requests, which lack nonce validation and time limits, to repeatedly mint administrator access and refresh tokens. CVE-2026-61410 (9.4) is a missing-authorization flaw enabling unauthenticated remote command execution, and CVE-2026-80238 (9.3) is an exposed Docker socket allowing local privilege escalation to root and container escape. Fixes ship in appliance 5.36.00.16 and application 5.36.00.00.
- CVE-2026-80172: request replay without nonce validation grants persistent admin tokens
- CVE-2026-61410: missing authorization enables unauthenticated remote command execution
- CVE-2026-80238: exposed Docker socket allows root escalation and container escape
- Compromise could provide a foothold into environments with Dell-managed critical infrastructure
- Patch to 5.36.00.16/5.36.00.00 and review token-generation and SSH logs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-61410 +1 in the same advisory: …80238 | Missing Authorization Allows Unauthenticated RCE in Dell Secure Connect Gateway 5.0 CVE-2026-61410 is a missing-authorization flaw (CWE-862) in Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00. An unauthenticated attacker with remote network access can send specially crafted requests that bypass the application's intended restrictions on code execution, triggering remote command execution on the gateway host. Given the CVSS 9.4 vector (high confidentiality and integrity impact, low availability impact), a successful attacker effectively gains broad control over the system, and related reporting also describes unauthenticated RCE and admin access on affected SCG deployments. Any organization running the affected SCG 5.x builds — typically enterprises using SCG as the on-premises gateway that connects Dell EMC infrastructure to Dell support services — is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates a modest 1.3% probability of exploitation within 30 days. Do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later, per Dell's advisory. Until patched, restrict network access to the SCG web interface (allowlists, VPN, or firewall rules) and avoid exposing it directly to the internet, and check gateway logs for unexpected or malformed requests. Inventory both appliance and application editions, since each has a separate fixed version. | 9.4 group max | 1% |
| largeon the order of tens of thousands of enterprise deployments (10k–100k systems; estimate | ||
| CVE-2026-80172 | Unauthenticated Token Replay Flaw in Dell Secure Connect Gateway 5.0 Dell Secure Connect Gateway (SCG) 5.0 contains an Insufficient Verification of Data Authenticity flaw (CWE-345) that lets an unauthenticated remote attacker replay a previously captured request to obtain ADMIN access and refresh tokens. Because the product performs no nonce validation and imposes no time limit on requests, the same captured request can be reused indefinitely to mint new privileged tokens. An attacker gains persistent, unauthorized administrative access to the gateway, which serves as the connectivity hub between Dell customer environments and Dell support services. Organizations running SCG 5.0 Appliance prior to 5.36.00.16 or SCG 5.0 Application prior to 5.36.00.00 are affected. Exploitation has not been observed so far: EPSS puts 30-day exploitation probability at 0.3%, the flaw is not in CISA KEV, and no public proof-of-concept is known. Do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later as soon as possible. Until patched, restrict network access to the gateway's interface to trusted hosts and review recent authentication activity, since any captured request can be replayed indefinitely to obtain ADMIN tokens; consider rotating credentials and tokens if unauthorized access is suspected. | 9.8 | <1% |
| largeon the order of tens of thousands of enterprise deployments worldwide |
Full article545 words · extracted from cybersecuritynews.com · click to collapse
Dell has disclosed three critical vulnerabilities in its Secure Connect Gateway 5.0 platform that could allow attackers to gain unauthorized access, execute commands remotely, and obtain root-level control of affected systems.
The flaws affect Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00.
Dell has urged customers to upgrade as soon as possible because the issues could expose support-management infrastructure to serious compromise.
Organizations use Secure Connect Gateway to connect Dell infrastructure with Dell support services for monitoring, diagnostics, and automated service requests. A successful attack on the platform could therefore give an attacker a foothold in environments containing critical enterprise infrastructure.
The most severe issue, tracked as CVE-2026-80172, is an insufficient data-authenticity verification flaw with a CVSS score of 9.8. An unauthenticated remote attacker could exploit captured requests to create administrator access tokens and refresh tokens repeatedly.
Dell Secure Connect Gateway Vulnerabilities
According to Dell’s advisory, the affected implementation does not enforce nonce validation or a request time limit. This means an attacker who captures a valid request may be able to replay it indefinitely. The weakness could enable persistent unauthorized administrative access without requiring valid login credentials.
A second vulnerability, CVE-2026-61410, is a missing authorization issue rated 9.4 on the CVSS scale. An unauthenticated attacker with remote access could send a specially crafted request to the Secure Connect Gateway application and bypass intended restrictions on code execution.
Successful exploitation could allow remote command execution on the affected system. Attackers could use this access to run malicious commands, collect sensitive data, alter configurations, deploy persistence mechanisms, or move laterally across the network.
The third flaw, CVE-2026-80238, has a CVSS score of 9.3 and involves execution with unnecessary privileges. The vulnerability requires local access, but it could allow a low-privileged operator with SSH access to the Secure Connect Gateway host to gain root-level privileges.
The issue stems from an exposed Docker socket. A low-privileged user could leverage the socket to access the host environment without requiring a password.
Dell also warned that an attacker who compromises a service inside the orchestrator container could access the same Docker socket, escape the container boundary, and take control of the underlying host. Together, the vulnerabilities create multiple paths to compromise affected Secure Connect Gateway deployments fully.
An attacker could potentially obtain administrator tokens through request replay, execute commands remotely through authorization bypass, or escalate privileges through the Docker socket exposure. Organizations using Dell Secure Connect Gateway should identify affected appliance and application deployments immediately.
Administrators should upgrade Appliance installations to version 5.36.00.16 or later and Application installations to version 5.36.00.00 or later.
Security teams should also review Secure Connect Gateway logs for suspicious token-generation activity, unusual API requests, unexpected remote command execution, and unauthorized SSH sessions.
Restrict network access to management interfaces to trusted administrative networks, and limit and monitor SSH access. Dell classified all three issues as critical and recommends immediate remediation to prevent unauthorized access and possible host-level compromise.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/dell-secure-connect-gateway-vulnerabilities/