Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access
Action: Patch
AI Analysis

Impact

Dell’s Secure Connect Gateway 5.0 Appliance and Application have a critical missing‑authentication flaw that may allow an attacker who can reach the device over the network to gain unrestricted access to sensitive configuration and control functions. The flaw is described as a Missing Authentication for Critical Function; an unauthenticated attacker with remote access could potentially alter settings or elevate privileges, which compromises confidentiality, integrity, and availability of the gateway services. The weakness is classified as CWE‑306, a lack of authentication for operations that rely on authenticated sessions.

Affected Systems

Both the Dell Secure Connect Gateway 5.0 Appliance and the Application are impacted. In particular, versions prior to 5.36.00.16 on the Appliance and earlier than 5.36.00.00 on the Application contain the flaw. Administrators should check the version of their installation against these thresholds to determine if the device is vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk level; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an unauthenticated adversary establishing a remote connection to the gateway’s management interface and then exploiting the missing authentication to perform critical functions. Because the flaw is not tied to a web‑interface specific injection, exploitation depends on network reachability and the absence of any authentication controls at the network layer.

Generated by OpenCVE AI on September 9, 2026 at 13:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway 5.0 firmware update provided in DSA‑2026‑382, which removes the authentication bypass in the critical functions.
  • Upgrade the Appliance to version 5.36.00.16 or newer and the Application to 5.36.00.00 or newer to ensure the vulnerability is patched.
  • Restrict remote access to the gateway’s management interface through firewall rules or VPN restrictions so that only trusted networks can reach it; temporarily disable public exposure of the management port until a patch is applied.

Generated by OpenCVE AI on September 9, 2026 at 13:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Missing Authentication Allows Unauthorized Access in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T16:00:27.133Z

Reserved: 2026-08-25T16:04:25.340Z

Link: CVE-2026-79961

cve-icon Vulnrichment

Updated: 2026-09-09T15:51:43.974Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T13:20:38.517

Modified: 2026-09-09T20:12:30.943

Link: CVE-2026-79961

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:30:16Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function