Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell’s Secure Connect Gateway 5.0 Appliance and Application have a critical missing‑authentication flaw that may allow an attacker who can reach the device over the network to gain unrestricted access to sensitive configuration and control functions. The flaw is described as a Missing Authentication for Critical Function; an unauthenticated attacker with remote access could potentially alter settings or elevate privileges, which compromises confidentiality, integrity, and availability of the gateway services. The weakness is classified as CWE‑306, a lack of authentication for operations that rely on authenticated sessions.

Affected Systems

Both the Dell Secure Connect Gateway 5.0 Appliance and the Application are impacted. In particular, versions prior to 5.36.00.16 on the Appliance and earlier than 5.36.00.00 on the Application contain the flaw. Administrators should check the version of their installation against these thresholds to determine if the device is vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk level; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an unauthenticated adversary establishing a remote connection to the gateway’s management interface and then exploiting the missing authentication to perform critical functions. Because the flaw is not tied to a web‑interface specific injection, exploitation depends on network reachability and the absence of any authentication controls at the network layer.

Generated by OpenCVE AI on September 9, 2026 at 13:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway 5.0 firmware update provided in DSA‑2026‑382, which removes the authentication bypass in the critical functions.
  • Upgrade the Appliance to version 5.36.00.16 or newer and the Application to 5.36.00.00 or newer to ensure the vulnerability is patched.
  • Restrict remote access to the gateway’s management interface through firewall rules or VPN restrictions so that only trusted networks can reach it; temporarily disable public exposure of the management port until a patch is applied.

Generated by OpenCVE AI on September 9, 2026 at 13:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Missing Authentication Allows Unauthorized Access in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T16:00:27.133Z

Reserved: 2026-08-25T16:04:25.340Z

Link: CVE-2026-79961

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T13:20:38.517

Modified: 2026-09-09T15:38:39.083

Link: CVE-2026-79961

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T13:30:10Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function