Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 3.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a least privilege violation present in Dell Secure Connect Gateway 5.0 Appliance and Application. A high-privileged attacker with local access could potentially exploit the flaw to gain unauthorized access.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected.

Risk and Exploitability

The CVSS score of 3.4 indicates a low severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access and is limited to users with high-privilege rights, so the attack vector is inferred to be local but privileged.

Generated by OpenCVE AI on September 9, 2026 at 16:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway 5.0 security update per DSA-2026-382, which patches the lowest-privilege flaw.
  • Review local accounts and remove unnecessary administrative permissions to enforce strict least privilege.
  • Enable monitoring of privileged account activity to detect and respond to abuse.

Generated by OpenCVE AI on September 9, 2026 at 16:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Dell Secure Connect Gateway 5.0 Local Privilege Escalation Vulnerability

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-272
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T16:10:00.153Z

Reserved: 2026-08-25T15:04:54.601Z

Link: CVE-2026-79944

cve-icon Vulnrichment

Updated: 2026-09-09T16:09:55.347Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T16:17:08.403

Modified: 2026-09-09T19:55:14.207

Link: CVE-2026-79944

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:30:16Z

Weaknesses
  • CWE-272

    Least Privilege Violation