Description
Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Published: 2026-09-07
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway (SCG) 5.0 prior to 5.36.00.00 suffers from an OS Command Injection flaw where an attacker can supply unsanitized input that is passed to the operating system shell. The vulnerability allows unprivileged, unauthenticated remote users to execute arbitrary system commands, potentially compromising the entire gateway service.

Affected Systems

The issue affects Dell Secure Connect Gateway 5.0 Application and Dell Secure Connect Gateway 5.0 – Appliance for all releases earlier than 5.36.00.00.

Risk and Exploitability

The CVSS score of 7.3 indicates a high impact potential, and although an EPSS score is not available, the flaw is not listed in the CISA KEV catalog. Unauthenticated remote attackers can exploit this weakness, which could lead to complete takeover of the appliance if no network restrictions are in place.

Generated by OpenCVE AI on September 7, 2026 at 14:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell security update that lifts the issue to version 5.36.00.00 or later, available through the Dell support portal.
  • If an immediate update is infeasible, block or restrict remote access to the SCG appliance to trusted IP ranges only to mitigate exposure.
  • Employ input validation on any exposed command interfaces and log all command execution attempts for forensic readiness.

Generated by OpenCVE AI on September 7, 2026 at 14:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell Secure Connect Gateway 5.0 Allows Unauthenticated Remote Execution

Mon, 07 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T12:19:34.175Z

Reserved: 2026-07-09T11:05:01.705Z

Link: CVE-2026-61409

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T13:20:33.720

Modified: 2026-09-07T13:20:33.720

Link: CVE-2026-61409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')