Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
Published: 2026-09-09
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Dell Secure Connect Gateway 5.0 Appliance and Application versions before 5.36.00.16/5.36.00.00 arises from improper handling of highly compressed data, allowing data amplification. An unauthenticated attacker who can reach the device over the network can trigger the flaw, causing the system to consume excessive resources and become unavailable. This flaw corresponds to the CWE‑409 weakness of improper resource management.

Affected Systems

Affected are Dell Secure Connect Gateway 5.0 Appliance and Application deployments. Specifically, any installation using Appliance version earlier than 5.36.00.16 or Application earlier than 5.36.00.00. The vulnerability is present in all device firmware and application containers that expose the vulnerable data processing routines to external traffic.

Risk and Exploitability

The flaw carries a CVSS score of 7.3, indicating a high severity. Since no EPSS data is published, current exploit probability cannot be quantified; the vulnerability is not listed in the CISA KEV catalog. The attack can be achieved remotely without authentication, making the risk practical for attackers who obtain network connectivity to the gateway. Mitigation relies on applying the Dell retainer update that resolves the data amplification issue. In the absence of a patch, administrators should consider blocking or limiting highly compressed traffic to reduce the likelihood of a denial‑of‑service event.

Generated by OpenCVE AI on September 9, 2026 at 12:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway 5.0 security update version 5.36.00.16 or later (or equivalent Application update 5.36.00.00).
  • Restrict or filter incoming compressed data traffic to the gateway, or temporarily disable features that trigger the compression handler, to mitigate the data amplification risk.
  • Monitor CPU and memory usage on the appliance, and set alerts for abnormal spikes that could indicate an ongoing attack.

Generated by OpenCVE AI on September 9, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title High‑Compression Data Amplification Allowing Remote Denial of Service in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
Weaknesses CWE-409
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T11:31:28.209Z

Reserved: 2026-08-25T12:04:33.630Z

Link: CVE-2026-79695

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T12:17:14.250

Modified: 2026-09-09T12:17:14.250

Link: CVE-2026-79695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:30:09Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)