Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Remote Access
Action: Prompt Patch
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 exposes an Improper Authentication vulnerability that allows a low‑privileged attacker with remote access to bypass normal authentication controls. The flaw can lead to unauthorized access to management interfaces and potentially to the underlying appliance or application resources. The weakness is a classic authentication bypass, categorized as CWE‑287.

Affected Systems

The vulnerability affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. Both the appliance and application components listed under Dell’s Secure Connect Gateway product line are susceptible.

Risk and Exploitability

The CVSS score of 6.4 places this flaw in the moderate severity range. No EPSS score is published, so the current exploitation probability is unknown, and it is not listed in the CISA KEV catalog. The attack vector is remote, requiring only low‑privilege or guest access to trigger the authentication failure. Because the flaw permits bypassing authentication, successful exploitation could provide an attacker with full control over configuration and potentially data exfiltration.

Generated by OpenCVE AI on September 9, 2026 at 10:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Secure Connect Gateway 5.0 Appliance to version 5.36.00.16 or later and upgrade the Application to 5.36.00.00 or newer, following Dell’s security update documentation.
  • Apply any additional Dell security patches and updates released for Secure Connect Gateway to ensure all related components are hardened.
  • Restrict remote management access to trusted IP ranges or apply network segmentation, and enable multi‑factor authentication wherever possible to reduce the risk of unauthorized access.

Generated by OpenCVE AI on September 9, 2026 at 10:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper Authentication in Dell Secure Connect Gateway 5.0 Enabling Unauthorized Remote Access

Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-11T03:56:29.411Z

Reserved: 2026-08-25T16:04:25.341Z

Link: CVE-2026-79974

cve-icon Vulnrichment

Updated: 2026-09-09T13:00:30.476Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T09:17:11.590

Modified: 2026-09-11T04:17:53.847

Link: CVE-2026-79974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:11:14Z

Weaknesses