Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.
Published: 2026-09-09
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an OS Command Injection flaw that allows an attacker with low privileges and local access to run arbitrary shell commands on Dell Secure Connect Gateway 5.0 appliances and applications. The improper neutralization of special elements in command strings could let the attacker gain control over the underlying operating system or execute privileged operations, potentially leading to a full compromise of the device.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. Systems running these versions could be exploited by local attackers who have limited privileges on the device. The vulnerability does not affect newer releases beyond the stated cut‑off versions.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while no EPSS score is currently available. The vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation at present. An attacker would need local access and low privileges; the flaw is exploitable from within the appliance or application context, making the attack surface limited to machines or users already on the same network or system.

Generated by OpenCVE AI on September 9, 2026 at 16:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell SCG 5.36.00.16 update for the Appliance and the Dell SCG 5.36.00.00 update for the Application as issued in the Dell Security Update for SCG 5.0; this patch resolves the command injection flaw.
  • If updating immediately is not possible, restrict local logins to administrators and disable any features that accept untrusted command parameters to reduce the chance of exploitation.
  • Configure network segmentation or firewall rules to prevent unauthenticated local connections to the SCG appliance or application, thereby limiting exposure to users who lack even low privileges.

Generated by OpenCVE AI on September 9, 2026 at 16:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell Secure Connect Gateway 5.0 Allowing Local Command Execution

Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T15:55:57.011Z

Reserved: 2026-08-24T17:05:26.110Z

Link: CVE-2026-78493

cve-icon Vulnrichment

Updated: 2026-09-09T15:55:53.406Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T16:17:06.640

Modified: 2026-09-09T19:59:14.270

Link: CVE-2026-78493

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T16:45:13Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')