Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.
Published: 2026-09-09
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 appliances and applications contain an Improper Neutralization of Special Elements used in an LDAP Query, known as LDAP injection. This weakness allows an unauthenticated attacker with remote access to construct malicious LDAP queries that can inject arbitrary script code. The impact may include unauthorized data access and the possibility of executing the injected scripts if the system processes them, potentially leading to further compromise.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. The vulnerability applies to both the appliance and application components referenced by Dell.

Risk and Exploitability

The CVSS score of 4.4 indicates a moderate severity level, and no EPSS score is publicly available. This vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation at the time of this analysis. An attacker could potentially exploit the flaw remotely without authentication, but the lack of a high exploitability score reduces immediate risk. Organizations should consider the attack vector as remote and unauthenticated access to the LDAP service.

Generated by OpenCVE AI on September 9, 2026 at 10:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell DSA‑2026‑382 security update for Secure Connect Gateway virtual edition.
  • Restrict external or unauthenticated access to the LDAP query interface to prevent injection attempts.
  • Ensure that any input processed by LDAP queries is properly escaped or validated to mitigate injection.

Generated by OpenCVE AI on September 9, 2026 at 10:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title LDAP Injection Vulnerability in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.
Weaknesses CWE-90
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T13:02:07.755Z

Reserved: 2026-08-25T18:04:39.714Z

Link: CVE-2026-80055

cve-icon Vulnrichment

Updated: 2026-09-09T13:02:04.711Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T08:17:22.263

Modified: 2026-09-09T15:38:39.083

Link: CVE-2026-80055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:15:09Z

Weaknesses
  • CWE-90

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')