Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-07
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a Missing Authentication for a critical function that allows an unauthenticated attacker with remote access to gain unauthorized control. Because authentication is not required, an attacker could trigger privileged actions within the appliance or application, potentially altering configuration, accessing sensitive data, or enabling further compromise. The impact is mainly to confidentiality and integrity, as the attacker can read or modify protected resources without any credential check.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, and while the EPSS score is not available, the lack of the vulnerability in the KEV catalog suggests it has not yet seen widespread exploitation. The likely attack vector is remote; an attacker only needs network connectivity to the appliance or application and no authentication. If successful, the attacker can obtain unauthorized access to critical functions.

Generated by OpenCVE AI on September 7, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway 5.0 Appliance update to version 5.36.00.16 or later and the Application update to 5.36.00.00 or later as published in the Dell security update.
  • If upgrading immediately is not possible, isolate the appliance or application from untrusted networks and restrict remote management access until the patch is installed.
  • Configure network segmentation or firewall rules to allow only trusted management networks to reach the appliance or application and verify that authentication mechanisms are enforced for all privileged interfaces.

Generated by OpenCVE AI on September 7, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Missing Authentication in Dell Secure Connect Gateway 5.0 Enables Unauthenticated Remote Access

Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T14:04:57.539Z

Reserved: 2026-08-25T10:35:45.861Z

Link: CVE-2026-79645

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T15:17:32.033

Modified: 2026-09-07T15:17:32.033

Link: CVE-2026-79645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:30:06Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function