Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control of File Name or Path vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker.
Published: 2026-09-09
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker with remote access can control file names or paths on Dell Secure Connect Gateway 5.0, enabling the reading or writing of arbitrary files on the host. This elevation can reveal sensitive configuration data or allow malicious modifications, compromising system confidentiality and integrity. The flaw reflects CWE-73, an external control of file name or path weakness.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance models older than version 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application models older than version 5.36.00.00 are impacted. Only the appliance and application components of the SCG 5.0 series are affected by this vulnerability.

Risk and Exploitability

The CVSS score of 7.3 indicates a high‑severity flaw, and although EPSS information is not available, the lack of a KEV listing suggests that widespread exploitation has not yet been observed. The likely attack vector is remote and unauthenticated, meaning that an attacker could exploit the weakness over any network connection that reaches the gateway’s management interface, potentially resulting in filesystem access if successful.

Generated by OpenCVE AI on September 9, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell’s latest security update for Secure Connect Gateway 5.0, which addresses the path traversal flaw.
  • Restrict remote access to the SCG Appliance and Application by enforcing authentication or firewall rules, limiting attackers who can reach the vulnerable interface.
  • Sanitize and validate all user‑supplied file names or paths in any SCG configuration or API to eliminate uncontrolled path traversal.

Generated by OpenCVE AI on September 9, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title External Control of File Name or Path Enables Remote Filesystem Access in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control of File Name or Path vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker.
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T11:40:06.809Z

Reserved: 2026-08-25T12:04:33.630Z

Link: CVE-2026-79692

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T12:17:14.120

Modified: 2026-09-09T12:17:14.120

Link: CVE-2026-79692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:30:09Z

Weaknesses
  • CWE-73

    External Control of File Name or Path