ZeroHour
GBHackerspublished ()ingested Divya

Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access

AI summary · glm-5.3-flash

Dell patched three critical Secure Connect Gateway flaws (CVE-2026-80172 up to CVSS 9.8) enabling unauthenticated admin access, remote code execution, and host takeover.

Dell Security Advisory DSA-2026-382 fixes three critical vulnerabilities in Secure Connect Gateway (SCG) 5.0, affecting appliances earlier than 5.36.00.16 and applications earlier than 5.36.00.00. CVE-2026-80172 (CVSS 9.8) allows unauthenticated replay of captured requests to obtain ADMIN access due to missing nonce and time validation; CVE-2026-61410 (9.4) enables unauthenticated command execution via missing authorization; CVE-2026-80238 (9.3) involves an exposed Docker socket allowing root access and container escape. Dell urges immediate upgrades and recommends restricting management interfaces to trusted networks and rotating credentials if compromise is suspected.

  • CVE-2026-80172 (9.8): request replay without nonce/time validation yields ADMIN access
  • CVE-2026-61410 (9.4): missing authorization allows unauthenticated command execution
  • CVE-2026-80238 (9.3): exposed Docker socket enables root and container escape
  • Affects SCG appliances before 5.36.00.16, applications before 5.36.00.00
  • Dell urges immediate upgrades and restricting management interfaces

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-61410
+1 in the same advisory: …80238
Missing Authorization Allows Unauthenticated RCE in Dell Secure Connect Gateway 5.0

CVE-2026-61410 is a missing-authorization flaw (CWE-862) in Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00. An unauthenticated attacker with remote network access can send specially crafted requests that bypass the application's intended restrictions on code execution, triggering remote command execution on the gateway host. Given the CVSS 9.4 vector (high confidentiality and integrity impact, low availability impact), a successful attacker effectively gains broad control over the system, and related reporting also describes unauthenticated RCE and admin access on affected SCG deployments. Any organization running the affected SCG 5.x builds — typically enterprises using SCG as the on-premises gateway that connects Dell EMC infrastructure to Dell support services — is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates a modest 1.3% probability of exploitation within 30 days.

Do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later, per Dell's advisory. Until patched, restrict network access to the SCG web interface (allowlists, VPN, or firewall rules) and avoid exposing it directly to the internet, and check gateway logs for unexpected or malformed requests. Inventory both appliance and application editions, since each has a separate fixed version.

9.4
group max
1%
  • Dell Secure Connect Gateway (SCG) 5.0 Appliance all versions prior to 5.36.00.16
  • Dell Secure Connect Gateway (SCG) 5.0 Application all versions prior to 5.36.00.00
largeon the order of tens of thousands of enterprise deployments (10k–100k systems; estimate
CVE-2026-80172
Unauthenticated Token Replay Flaw in Dell Secure Connect Gateway 5.0

Dell Secure Connect Gateway (SCG) 5.0 contains an Insufficient Verification of Data Authenticity flaw (CWE-345) that lets an unauthenticated remote attacker replay a previously captured request to obtain ADMIN access and refresh tokens. Because the product performs no nonce validation and imposes no time limit on requests, the same captured request can be reused indefinitely to mint new privileged tokens. An attacker gains persistent, unauthorized administrative access to the gateway, which serves as the connectivity hub between Dell customer environments and Dell support services. Organizations running SCG 5.0 Appliance prior to 5.36.00.16 or SCG 5.0 Application prior to 5.36.00.00 are affected. Exploitation has not been observed so far: EPSS puts 30-day exploitation probability at 0.3%, the flaw is not in CISA KEV, and no public proof-of-concept is known.

Do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later as soon as possible. Until patched, restrict network access to the gateway's interface to trusted hosts and review recent authentication activity, since any captured request can be replayed indefinitely to obtain ADMIN tokens; consider rotating credentials and tokens if unauthorized access is suspected.

9.8<1%
  • Dell Secure Connect Gateway (SCG) 5.0 Appliance All versions prior to 5.36.00.16
  • Dell Secure Connect Gateway (SCG) 5.0 Application All versions prior to 5.36.00.00
largeon the order of tens of thousands of enterprise deployments worldwide
Full article525 words · extracted from gbhackers.com · click to collapse

Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities.

These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise.

Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions earlier than 5.36.00.00.

Dell strongly urges affected organizations to upgrade immediately, citing the severity of these vulnerabilities and the risk of complete compromise of exposed gateways.

Dell Secure Connect Gateway Critical Flaws

The first issue, CVE-2026-80172, is rated 9.8 under CVSS v3.1 and involves insufficient verification of data authenticity. According to Dell, a remote, unauthenticated attacker could repeatedly replay a captured request to gain ADMIN access and refresh tokens.

The request-handling process lacks nonce validation and a time limit, allowing replay attempts to continue indefinitely. This vulnerability requires no privileges or user interaction.

It affects confidentiality, integrity, and availability, making it particularly dangerous when SCG interfaces are accessible from untrusted networks.

The second issue, CVE-2026-61410, has a CVSS score of 9.4 and arises from missing authorization. Dell states that an unauthenticated remote attacker can send a specially crafted request to the application, bypass intended restrictions on code execution, and execute commands on the target system.

Successful exploitation could give the intruder direct access to a support-management platform, which often contains valuable operational data and privileged connectivity.

While the impact on availability is rated low, the potential for high confidentiality and integrity impact, along with the ability to execute remote commands, allows for follow-on actions such as credential theft, persistence, lateral movement, or data exfiltration.

The third issue, CVE-2026-80238, carries a score of 9.3 and concerns execution with unnecessary privileges. The advisory describes an exposed Docker socket that allows a low-privileged operator with SSH access to obtain root-level access to the SCG host without a password.

Dell also warns that compromising a service within the orchestrator container could provide access to the same socket, leading to container escape and host takeover.

Although this risk requires local access, it significantly increases the potential post-compromise risk. It can turn limited access into total control of the appliance.

Secure Connect Gateway is designed to centralize monitoring and support connectivity. Therefore, treat these vulnerabilities as potentially high-impact infrastructure exposures.

Organizations should inventory both appliance and application installations, confirm their exact versions, and upgrade to the remediated versions specified by Dell.

Administrators should also review internet exposure, restrict management interfaces to trusted networks, rotate credentials and tokens when compromise is suspected, and examine logs for unusual requests, unexpected administrative sessions, command execution, or container-related activity.

Organizations must prioritize these updates, as the two remote flaws require neither authentication nor user interaction. If upgrades cannot be performed, isolating SCG systems, limiting access paths, and monitoring for exploitation may help reduce exposure. However, these measures are not substitutes for Dell’s fixes.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/dell-secure-connect-gateway-critical-flaws/