Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker.
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Filesystem Access via Path Traversal
Action: Apply Patch
AI Analysis

Impact

A relative path traversal flaw exists in Dell Secure Connect Gateway 5.0 Appliance and Application. An unauthenticated attacker who can reach the device remotely could cause a path traversal that allows reading of arbitrary files on the device&#39;s filesystem. The weakness, classified as CWE-23, undermines file system isolation and may expose configuration data, credentials, or other sensitive information.

Affected Systems

Affected versions are Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. Both product lines are deployed in organizations that use Dell&#39;s secure connectivity platform.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is "remote unauthenticated access" to the gateway. Exploitation would require the attacker to send a specially crafted request that triggers the path traversal during file retrieval or configuration access. No public exploit code has been reported at this time, but the potential for remote unauthorized file disclosure remains if the gateway remains reachable from an untrusted network.

Generated by OpenCVE AI on September 9, 2026 at 13:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell Secure Connect Gateway 5.0 patch to version 5.36.00.16 for Appliance and 5.36.00.00 for Application as provided in Dell Security Advisory DSA-2026-382.
  • Restrict remote management access to the Secure Connect Gateway devices to trusted networks or VPNs, reducing exposure to unauthenticated attackers.
  • Monitor device logs for anomalous file access attempts and configure alerting for path traversal patterns.

Generated by OpenCVE AI on September 9, 2026 at 13:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Relative Path Traversal Vulnerability in Dell Secure Connect Gateway 5.0 Allowing Remote Unauthenticated Filesystem Access

Wed, 09 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker.
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-14T13:10:59.225Z

Reserved: 2026-08-25T14:04:56.064Z

Link: CVE-2026-79728

cve-icon Vulnrichment

Updated: 2026-09-14T13:10:55.379Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T13:20:38.290

Modified: 2026-09-14T14:17:11.123

Link: CVE-2026-79728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:15:06Z

Weaknesses
  • CWE-23

    Relative Path Traversal