Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A race condition in Dell Secure Connect Gateway 5.0 Appliance and Application allows an attacker to thread concurrent operations on shared resources, resulting in improper synchronization. If exploited, an unauthenticated attacker with remote access can trigger a denial of service by corrupting shared state or exhausting system resources. This flaw is categorized as CWE‑567.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions older than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions older than 5.36.00.00 are affected. The vulnerability applies to both appliance and application deployments listed by Dell as insecure prior to the specified patch releases.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and no EPSS value is available, implying limited data on real‑world exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not yet widely exploited. However, the attack vector is likely remote and unauthenticated, meaning any host reachable over the network could be targeted to cause service disruption. Organizations should evaluate exposure based on their network segmentation and exposure to remote access.

Generated by OpenCVE AI on September 9, 2026 at 16:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell security update DSA‑2026‑382 to the affected SCG 5.0 Appliance and Application to eliminate the race condition flaw.
  • Upgrade the appliance to version 5.36.00.16 or later and the application to version 5.36.00.00 or later, which include the fix.
  • If immediate upgrades are not possible, restrict or disable remote access to the SCG service to reduce the attack surface.

Generated by OpenCVE AI on September 9, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Race condition in Dell Secure Connect Gateway 5.0 allows remote denial of service

Wed, 09 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
Weaknesses CWE-567
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-14T13:11:37.043Z

Reserved: 2026-08-25T16:04:25.341Z

Link: CVE-2026-79969

cve-icon Vulnrichment

Updated: 2026-09-14T13:11:31.209Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T13:20:39.827

Modified: 2026-09-14T14:17:11.883

Link: CVE-2026-79969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:30:16Z

Weaknesses
  • CWE-567

    Unsynchronized Access to Shared Data in a Multithreaded Context