Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an improper neutralization of special elements used in an SQL command, enabling a remote attacker with high privileges to conduct a SQL injection attack against Dell Secure Connect Gateway 5.0. The injection could allow the attacker to alter or retrieve data stored in the underlying database, leading to unauthorized access to configuration settings or sensitive information. The weakness is identified as CWE-89. No additional code execution is explicitly described, but the possibility of gaining privileged database access constitutes a serious breach of confidentiality and integrity for the affected system.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance and Application firmware versions prior to 5.36.00.16 and 5.36.00.00, respectively, are impacted. Any deployment of these older versions remains at risk until the latest patch is applied.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. The EPSS score is not available, so precise exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA KEV, implying no confirmed widespread exploitation yet. The likely attack vector is remote, requiring an attacker to have high privileged remote access to the gateway—either through a compromised management interface or an exposed administrative endpoint. Once accessed, the attacker could exploit the SQL injection to manipulate or read privileged data.

Generated by OpenCVE AI on September 9, 2026 at 13:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway 5.0 firmware update provided in Dell DSA‑2026‑382, upgrading the Appliance to version 5.36.00.16 and the Application to 5.36.00.00.
  • Restrict remote management access to the SCG to trusted IP ranges or VPN tunnels, minimizing the attack surface for privileged remote users.
  • Ensure that any database accounts used by the SCG have the least privilege necessary, limiting the potential impact if SQL injection were exploited.

Generated by OpenCVE AI on September 9, 2026 at 13:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title SQL Injection in Dell Secure Connect Gateway 5.0 Allowing Unauthorized Access

Wed, 09 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T16:00:48.125Z

Reserved: 2026-08-25T16:04:25.341Z

Link: CVE-2026-79972

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T12:17:14.760

Modified: 2026-09-09T15:38:39.083

Link: CVE-2026-79972

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T13:30:10Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')