Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access
Published: 2026-09-09
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper limitation of pathname to a restricted directory in Dell Secure Connect Gateway 5.0 allows an unauthenticated remote attacker to perform path traversal, potentially accessing or modifying files outside the intended directory structure. This can lead to unauthorized read or write operations, giving the attacker control over critical configuration files or other sensitive data.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. The vulnerability is present in both the appliance and the application components of the Secure Connect Gateway platform released by Dell.

Risk and Exploitability

The CVSS base score of 7.3 indicates a high risk level. Although the EPSS score is not reported, the lack of a KEV listing does not diminish the potential for exploitation via unauthenticated remote access. An attacker can exploit this path traversal flaw without credentials, making it easier to gain unauthorized access to the gateway's file system if the device is exposed to an untrusted network.

Generated by OpenCVE AI on September 9, 2026 at 12:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Secure Connect Gateway Appliance to version 5.36.00.16 or later.
  • Upgrade Dell Secure Connect Gateway Application to version 5.36.00.00 or later.
  • Restrict remote administrative access to trusted networks only, or disable remote access if not required.

Generated by OpenCVE AI on September 9, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Dell Secure Connect Gateway 5.0 Allowing Unauthorized Remote Access

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T12:02:13.469Z

Reserved: 2026-08-24T17:05:26.109Z

Link: CVE-2026-78485

cve-icon Vulnrichment

Updated: 2026-09-09T12:02:10.697Z

cve-icon NVD

Status : Received

Published: 2026-09-09T12:17:13.457

Modified: 2026-09-09T13:20:35.037

Link: CVE-2026-78485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:30:09Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')