Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 3.4 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 appliances and applications prior to the stated versions contain a least privilege violation that permits a highly privileged attacker with local access to bypass enforced restrictions and obtain unauthorized access to protected resources. The vulnerability originates from inadequate enforcement of local access controls within the software, enabling privileged users to elevate their permissions beyond intended limits. While the official description does not enumerate further damage, the possibility of unauthorized access undermines confidentiality and could facilitate additional exploitation if other weaknesses exist.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions before 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions before 5.36.00.00 are affected. The vulnerability applies to the appliance and application components under the Dell:Secure Connect Gateway 5.0 product line.

Risk and Exploitability

The CVSS score of 3.4 indicates a low to moderate severity, and the EPSS score is unavailable, implying limited insight into current exploitation rates. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. An attacker would need local high privileges to exploit the flaw, which implies that attackers with physical or administrative access to the device could potentially pivot to unauthorized configuration changes or read sensitive settings. Given the local attack requirement and the relatively low severity rating, the risk is moderate but should be addressed promptly to prevent privilege escalation that could lead to broader compromise.

Generated by OpenCVE AI on September 9, 2026 at 16:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Dell Secure Connect Gateway to version 5.36.00.16 or later
  • Restrict local console or privileged access to authorized administrators only
  • Disable or block unused local management interfaces to reduce attack surface
  • If upgrading is not immediately feasible, isolate the appliance from untrusted network segments to limit local privileged access

Generated by OpenCVE AI on September 9, 2026 at 16:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Least Privilege Violation Allowing Unauthorized Access in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-272
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T15:26:43.796Z

Reserved: 2026-08-25T12:04:33.630Z

Link: CVE-2026-79693

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T16:17:07.467

Modified: 2026-09-09T19:56:44.457

Link: CVE-2026-79693

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T16:45:13Z

Weaknesses
  • CWE-272

    Least Privilege Violation