Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 3.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized local access
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an execution with unnecessary privileges that allows a highly privileged attacker to elevate their privileges and gain unauthorized access to the system. This flaw does not directly expose remote code execution or denial of service, but it permits local attackers to bypass intended security boundaries and access sensitive data or services. The weakness is identified as CWE-250, where an application incorrectly allows users to perform privileged actions better than intended.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance and Application earlier than version 5.36.00.16 for the appliance and earlier than 5.36.00.00 for the application are affected. These appliances are used to provide secure connectivity for enterprise networks and rely on local administrative privileges for configuration and maintenance.

Risk and Exploitability

The CVSS score of 3.4 indicates low overall impact, but the absence of an EPSS score means exploitation likelihood is unknown. The flaw is not listed in the CISA KEV catalog, suggesting no publicly disclosed exploits. The attack requires high local privileges, therefore a local attacker with such access can exploit it. Once exploited, the attacker gains unauthorized access to resources beyond their intended scope.

Generated by OpenCVE AI on September 9, 2026 at 16:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Dell Secure Connect Gateway 5.0 security update 5.36.00.16 for appliances and 5.36.00.00 for applications as provided by Dell
  • Re‑evaluate local accounts and remove or restrict privileged user rights that are not required for normal operation
  • Disable or block unnecessary privileged services or network interfaces on the appliance and application to reduce attack surface

Generated by OpenCVE AI on September 9, 2026 at 16:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Local Access via Unnecessary Privileges in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-250
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T15:56:14.236Z

Reserved: 2026-08-25T15:04:54.601Z

Link: CVE-2026-79942

cve-icon Vulnrichment

Updated: 2026-09-09T15:56:11.008Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T16:17:08.270

Modified: 2026-09-09T19:55:46.567

Link: CVE-2026-79942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:30:16Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges