Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an improper neutralization of special elements used in an SQL command, enabling a remote attacker with high privileges to conduct a SQL injection attack against Dell Secure Connect Gateway 5.0. The injection could allow the attacker to alter or retrieve data stored in the underlying database, leading to unauthorized access to configuration settings or sensitive information. The weakness is identified as CWE-89. No additional code execution is explicitly described, but the possibility of gaining privileged database access constitutes a serious breach of confidentiality and integrity for the affected system.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance and Application firmware versions prior to 5.36.00.16 and 5.36.00.00, respectively, are impacted. Any deployment of these older versions remains at risk until the latest patch is applied.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. The EPSS score is not available, so precise exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA KEV, implying no confirmed widespread exploitation yet. The likely attack vector is remote, requiring an attacker to have high privileged remote access to the gateway—either through a compromised management interface or an exposed administrative endpoint. Once accessed, the attacker could exploit the SQL injection to manipulate or read privileged data.

Generated by OpenCVE AI on September 9, 2026 at 13:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway 5.0 firmware update provided in Dell DSA‑2026‑382, upgrading the Appliance to version 5.36.00.16 and the Application to 5.36.00.00.
  • Restrict remote management access to the SCG to trusted IP ranges or VPN tunnels, minimizing the attack surface for privileged remote users.
  • Ensure that any database accounts used by the SCG have the least privilege necessary, limiting the potential impact if SQL injection were exploited.

Generated by OpenCVE AI on September 9, 2026 at 13:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application
Vendors & Products Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application

Wed, 09 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title SQL Injection in Dell Secure Connect Gateway 5.0 Allowing Unauthorized Access

Wed, 09 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Secure Connect Gateway Secure Connect Gateway Appliance Secure Connect Gateway Application
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-11T03:56:22.974Z

Reserved: 2026-08-25T16:04:25.341Z

Link: CVE-2026-79972

cve-icon Vulnrichment

Updated: 2026-09-09T15:41:25.392Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T12:17:14.760

Modified: 2026-09-11T04:17:53.730

Link: CVE-2026-79972

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:45:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')