Description
Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Published: 2026-09-07
Score: 7.3 High
EPSS: 1.5% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An OS Command Injection flaw exists in Dell Secure Connect Gateway 5.0 versions prior to 5.36.00.00. The vulnerability results from improper neutralization of special elements used in an operating‑system command. It allows an unauthenticated attacker with remote access to supply crafted input that is passed to the underlying shell, enabling execution of arbitrary system commands. This could lead to compromise of the gateway service, potentially affecting the confidentiality and integrity of network traffic passing through the appliance.

Affected Systems

All Dell Secure Connect Gateway 5.0 (Application) and Dell Secure Connect Gateway 5.0 – Appliance deployments that are running a version earlier than 5.36.00.00 are affected. The issue does not apply to newer releases, including 5.36.00.00 and later.

Risk and Exploitability

The CVSS score of 7.3 reflects high impact potential. The EPSS score of 1 % indicates a low, but non‑zero, probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote network access to the SCG appliance; an attacker can trigger the flaw through unsanitized input sent over exposed interfaces. Successful exploitation would allow the attacker to execute arbitrary OS commands on the appliance.

Generated by OpenCVE AI on September 8, 2026 at 15:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell security update that releases Secure Connect Gateway 5.36.00.00 or later, obtainable from the Dell support portal.
  • If the update cannot be applied immediately, limit inbound traffic to the SCG appliance to a trusted, whitelisted IP range to reduce exposure.
  • Enable detailed logging of any command‑interface traffic and monitor for anomalous or unexpected command usage; consider implementing server‑side input validation for any exposed command endpoints.

Generated by OpenCVE AI on September 8, 2026 at 15:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
Vendors & Products Dell secure Connect Gateway

Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application
Vendors & Products Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application

Tue, 08 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell Secure Connect Gateway 5.0 Allows Unauthenticated Remote Execution

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell Secure Connect Gateway 5.0 Allows Unauthenticated Remote Execution

Mon, 07 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Dell Secure Connect Gateway Secure Connect Gateway Appliance Secure Connect Gateway Application
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-08T12:56:27.309Z

Reserved: 2026-07-09T11:05:01.705Z

Link: CVE-2026-61409

cve-icon Vulnrichment

Updated: 2026-09-08T12:56:24.205Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T13:20:33.720

Modified: 2026-09-16T01:15:33.650

Link: CVE-2026-61409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:37:24Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')