ZeroHour
Story · 1 source · 1 articlefirst updated ()1

Dell Patches Three Critical Secure Connect Gateway 5.0 Flaws (CVSS up to 9.8) Enabling Unauthenticated Admin Access and RCE

What's new: Initial merged summary (no prior story). Consolidates the 2026-09-08 GBHackers and Cyber Security News reports with no source conflicts: both agree on the three CVEs, CVSS scores (9.8/9.4/9.3), affected versions (<5.36.00.16 appliance, <5.36.00.00 application) and fixed versions (5.36.00.16 / 5.36.00.00). Single-source details preserved and attributed: DSA-2026-382 advisory ID (GBHackers);…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Dell Security Advisory DSA-2026-382 fixes three critical Secure Connect Gateway 5.0 vulnerabilities: CVE-2026-80172 (CVSS 9.8, unauthenticated admin access via request replay), CVE-2026-61410 (CVSS 9.4, unauthenticated remote command execution) and…

Two wire reports published on 2026-09-08 (GBHackers; Cyber Security News) cover Dell Security Advisory DSA-2026-382, which patches three critical vulnerabilities in Secure Connect Gateway (SCG) 5.0. CVE-2026-80172 (CVSS 9.8) lets unauthenticated attackers replay captured requests that lack nonce and time validation to obtain administrative (ADMIN) access; Cyber Security News adds that this can repeatedly mint administrator access and refresh tokens. CVE-2026-61410 (CVSS 9.4) is a missing-authorization flaw enabling unauthenticated remote command execution. CVE-2026-80238 (CVSS 9.3) involves an exposed Docker socket allowing privilege escalation to root and container escape. Affected deployments are SCG 5.0 appliances earlier than 5.36.00.16 and applications earlier than 5.36.00.00; fixes ship in appliance 5.36.00.16 and application 5.36.00.00. Dell urges immediate upgrades and recommends restricting management interfaces to trusted networks and rotating credentials if compromise is suspected; Cyber Security News also recommends reviewing token-generation and SSH logs and notes a compromise could provide a foothold into environments with Dell-managed critical infrastructure. The two sources agree on all technical details (CVEs, CVSS scores, affected and fixed versions); the advisory ID DSA-2026-382 appears only in the GBHackers report. Neither report claims active exploitation or provides exploit code.

  • Dell Security Advisory DSA-2026-382 fixes three critical vulnerabilities in Secure Connect Gateway (SCG) 5.0 (advisory ID reported by GBHackers)
  • CVE-2026-80172 (CVSS 9.8): replay of captured requests without nonce and time validation yields unauthenticated administrative (ADMIN) access; Cyber Security News notes it can repeatedly mint administrator access and refresh tokens
  • CVE-2026-61410 (CVSS 9.4): missing authorization enables unauthenticated remote command execution
  • CVE-2026-80238 (CVSS 9.3): exposed Docker socket allows privilege escalation to root and container escape
  • Affected versions: SCG 5.0 appliances earlier than 5.36.00.16 and applications earlier than 5.36.00.00
  • Fixed versions: appliance 5.36.00.16 and application 5.36.00.00
  • Vendor guidance: upgrade immediately, restrict management interfaces to trusted networks, and rotate credentials if compromise is suspected (Dell, per GBHackers); review token-generation and SSH logs (Cyber Security News)
  • Both reports dated 2026-09-08 agree on all CVEs, CVSS scores, affected versions and fixes; neither claims active exploitation

Coverage timeline

  1. · 7d ago
    GBHackers· 55
    Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access

    Dell patched three critical Secure Connect Gateway flaws (CVE-2026-80172 up to CVSS 9.8) enabling unauthenticated admin access, remote code execution, and host takeover.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-61410
+1 in the same advisory: …80238
Missing Authorization Allows Unauthenticated RCE in Dell Secure Connect Gateway 5.0

CVE-2026-61410 is a missing-authorization flaw (CWE-862) in Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00. An unauthenticated attacker with remote network access can send specially crafted requests that bypass the application's intended restrictions on code execution, triggering remote command execution on the gateway host. Given the CVSS 9.4 vector (high confidentiality and integrity impact, low availability impact), a successful attacker effectively gains broad control over the system, and related reporting also describes unauthenticated RCE and admin access on affected SCG deployments. Any organization running the affected SCG 5.x builds — typically enterprises using SCG as the on-premises gateway that connects Dell EMC infrastructure to Dell support services — is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates a modest 1.3% probability of exploitation within 30 days.

Do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later, per Dell's advisory. Until patched, restrict network access to the SCG web interface (allowlists, VPN, or firewall rules) and avoid exposing it directly to the internet, and check gateway logs for unexpected or malformed requests. Inventory both appliance and application editions, since each has a separate fixed version.

9.4
group max
1%
  • Dell Secure Connect Gateway (SCG) 5.0 Appliance all versions prior to 5.36.00.16
  • Dell Secure Connect Gateway (SCG) 5.0 Application all versions prior to 5.36.00.00
largeon the order of tens of thousands of enterprise deployments (10k–100k systems; estimate
CVE-2026-80172
Unauthenticated Token Replay Flaw in Dell Secure Connect Gateway 5.0

Dell Secure Connect Gateway (SCG) 5.0 contains an Insufficient Verification of Data Authenticity flaw (CWE-345) that lets an unauthenticated remote attacker replay a previously captured request to obtain ADMIN access and refresh tokens. Because the product performs no nonce validation and imposes no time limit on requests, the same captured request can be reused indefinitely to mint new privileged tokens. An attacker gains persistent, unauthorized administrative access to the gateway, which serves as the connectivity hub between Dell customer environments and Dell support services. Organizations running SCG 5.0 Appliance prior to 5.36.00.16 or SCG 5.0 Application prior to 5.36.00.00 are affected. Exploitation has not been observed so far: EPSS puts 30-day exploitation probability at 0.3%, the flaw is not in CISA KEV, and no public proof-of-concept is known.

Do: Upgrade SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later as soon as possible. Until patched, restrict network access to the gateway's interface to trusted hosts and review recent authentication activity, since any captured request can be replayed indefinitely to obtain ADMIN tokens; consider rotating credentials and tokens if unauthorized access is suspected.

9.8<1%
  • Dell Secure Connect Gateway (SCG) 5.0 Appliance All versions prior to 5.36.00.16
  • Dell Secure Connect Gateway (SCG) 5.0 Application All versions prior to 5.36.00.00
largeon the order of tens of thousands of enterprise deployments worldwide