Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Unsynchronized Access to Shared Data in a Multithreaded Context vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
Published: 2026-09-09
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability is an unsynchronized access to shared data in a multithreaded context, classified as CWE-567. An attacker with low privileges who can reach the system remotely may trigger a resource exhaustion condition, leading to denial of service of the Dell Secure Connect Gateway service.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are vulnerable. These products are commonly deployed in virtualized data center environments to provide secure remote access.

Risk and Exploitability

The CVSS score of 6.3 indicates medium severity. No EPSS score is available, so the probability of exploitation remains uncertain. The vulnerability is not listed in CISA KEV, suggesting no widespread exploitation reports. The likely attack vector is remote and requires low‑privilege access, with impact limited to service availability rather than confidentiality or privilege escalation.

Generated by OpenCVE AI on September 9, 2026 at 11:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell security update that upgrades the Appliance to at least 5.36.00.16 and the Application to at least 5.36.00.00
  • Restrict remote access to the Secure Connect Gateway by implementing firewall rules or VPN segmentation to reduce the attack surface
  • Configure system monitoring to detect abnormal resource consumption and alert administrators in case of potential denial of service incidents

Generated by OpenCVE AI on September 9, 2026 at 11:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unsynchronized Access to Shared Data Leading to Denial of Service in Dell Secure Connect Gateway

Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Unsynchronized Access to Shared Data in a Multithreaded Context vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
Weaknesses CWE-567
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T12:54:47.170Z

Reserved: 2026-08-25T16:04:25.341Z

Link: CVE-2026-79973

cve-icon Vulnrichment

Updated: 2026-09-09T12:54:42.727Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T09:17:11.473

Modified: 2026-09-09T19:46:09.447

Link: CVE-2026-79973

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:45:17Z

Weaknesses
  • CWE-567

    Unsynchronized Access to Shared Data in a Multithreaded Context