Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Incorrect Operator vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-07
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Use of Incorrect Operator flaw that allows an attacker who can reach the system remotely to bypass authentication controls and gain unauthorized access. This could lead to the attacker obtaining privileged data or taking control of the device. The weakness aligns with CWE‑480, an improper authorization issue.

Affected Systems

Dell Secure Connect Gateway version 5.0 Appliances prior to 5.36.00.16 and Application components prior to 5.36.00.00 are affected. All deployments of these products that have not applied a later firmware or software update are at risk.

Risk and Exploitability

The CVSS base score of 7.3 indicates a medium to high severity. No EPSS value is available, so the likelihood of exploitation is undetermined, but the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is inferred to be remote because the description states an unauthenticated attacker with remote access could exploit the flaw.

Generated by OpenCVE AI on September 7, 2026 at 16:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway firmware update 5.36.00.16 for Appliances and 5.36.00.00 for Application components as released on the Dell support site.
  • Ensure the device’s network interfaces are confined to trusted networks or protected by a firewall to block unsolicited remote connections.
  • Continuously monitor authentication and security logs for anomalous activity that may indicate an attempted or successful bypass.

Generated by OpenCVE AI on September 7, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Incorrect Operator vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-480
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T15:41:11.902Z

Reserved: 2026-08-25T10:35:45.861Z

Link: CVE-2026-79643

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T16:17:29.317

Modified: 2026-09-07T16:17:29.317

Link: CVE-2026-79643

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T17:00:11Z

Weaknesses
  • CWE-480

    Use of Incorrect Operator