Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Encoding or Escaping of Output vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to launch of phishing attacks.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Phishing through improper output encoding
Action: Immediate Patch
AI Analysis

Impact

The vulnerability involves improper encoding or escaping of output, permitting an attacker to inject or manipulate content that can be used to launch phishing attacks. An unauthenticated attacker with remote access could exploit this flaw, causing malicious content to be displayed to targets. This weakness corresponds to CWE‑116, where insufficient output encoding undermines confidentiality and integrity of user interfaces.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance running versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application running versions earlier than 5.36.00.00.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk, but the absence of an EPSS score and lack of listing in the KEV catalog suggest limited evidence of active exploitation. The likely attack vector is remote, with the attacker needing unauthenticated network access to the SCG services to exploit the output encoding flaw. Once exploited, the attacker could deceive users into interacting with malicious links or forms, potentially compromising user credentials or system integrity.

Generated by OpenCVE AI on September 9, 2026 at 16:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Dell SCG 5.0 Security Update to reach at least version 5.36.00.16 on Appliance and 5.36.00.00 on Application.
  • Disable or restrict unauthenticated remote access to SCG services until the update is applied.
  • Monitor system logs for signs of phishing or spoofed content delivery and review user access patterns.

Generated by OpenCVE AI on September 9, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Improper Output Encoding Enables Phishing via Dell Secure Connect Gateway
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Encoding or Escaping of Output vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to launch of phishing attacks.
Weaknesses CWE-116
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T15:34:24.295Z

Reserved: 2026-08-25T15:04:54.601Z

Link: CVE-2026-79952

cve-icon Vulnrichment

Updated: 2026-09-09T15:34:08.558Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:18.293

Modified: 2026-09-09T20:06:55.443

Link: CVE-2026-79952

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:30:16Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output