Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 includes a race condition bug that enables concurrent execution using a shared resource without proper synchronization. The flaw allows an unauthenticated attacker with remote access to trigger a denial of service by exhausting or corrupting shared state. The weakness is classified as a concurrent execution race condition (CWE-567).

Affected Systems

Versions of the Dell Secure Connect Gateway 5.0 Appliance before 5.36.00.16 and versions of the Dell Secure Connect Gateway 5.0 Application before 5.36.00.00 are vulnerable. The vulnerability applies to both the appliance and the application components of the product suite.

Risk and Exploitability

The vulnerability is scored with a moderate CVSS score of 5.3. EPSS is not available and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote, unauthenticated, and can be exercised by an external actor. Exploitation would cause service interruption for legitimate users but does not appear to provide confidentiality or integrity compromise.

Generated by OpenCVE AI on September 9, 2026 at 16:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Secure Connect Gateway Appliance to version 5.36.00.16 or later and upgrade the Application to version 5.36.00.00 or later per Dell’s security update.
  • Limit remote access to the SCG components to authenticated users or secure network segments until the patch is applied.
  • If possible, configure the appliance to reduce or serialize concurrent processes that use shared resources, or apply network segmentation to isolate the SCG from external traffic until the fix is deployed.

Generated by OpenCVE AI on September 9, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Concurrent Execution Race Condition in Dell Secure Connect Gateway 5.0 Leading to Denial of Service

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
Weaknesses CWE-567
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T14:08:51.348Z

Reserved: 2026-08-25T16:04:25.341Z

Link: CVE-2026-79962

cve-icon Vulnrichment

Updated: 2026-09-09T14:08:36.679Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T13:20:38.650

Modified: 2026-09-09T15:38:39.083

Link: CVE-2026-79962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T17:00:12Z

Weaknesses
  • CWE-567

    Unsynchronized Access to Shared Data in a Multithreaded Context