Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution.
Published: 2026-09-09
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch ASAP
AI Analysis

Impact

The vulnerability is a download of code without integrity check that allows an unauthenticated attacker with remote access to execute arbitrary commands on Dell Secure Connect Gateway 5.0 devices. The flaw is classified as CWE-494 and can result in full system compromise if exploited successfully.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are affected. These products must be identified and updated accordingly.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity. EPSS is not available, so the exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is an unauthenticated remote connection, such as via the public network interfaces exposed by the appliance or application. If an attacker can reach the vulnerable endpoint, the absence of an integrity check allows malicious code to be downloaded and executed, giving the attacker full control over the affected system.

Generated by OpenCVE AI on September 9, 2026 at 12:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway 5.0 security update (DSA-2026-382) to all vulnerable appliances and applications.
  • Verify that the appliance is upgraded to version 5.36.00.16 or later and the application to version 5.36.00.00 or later.
  • If an immediate upgrade is not possible, restrict external network access to the vulnerable devices until the update is applied.

Generated by OpenCVE AI on September 9, 2026 at 12:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application
Vendors & Products Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application

Fri, 11 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unverified Download in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution.
Weaknesses CWE-494
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Dell Secure Connect Gateway Secure Connect Gateway Appliance Secure Connect Gateway Application
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-11T13:06:07.218Z

Reserved: 2026-08-25T16:04:25.341Z

Link: CVE-2026-79963

cve-icon Vulnrichment

Updated: 2026-09-11T12:56:27.629Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T12:17:14.507

Modified: 2026-09-11T13:18:18.053

Link: CVE-2026-79963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:45:17Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check