Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Locking vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker.
Published: 2026-09-07
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper locking race condition in Dell Secure Connect Gateway 5.0 allows a low‑privileged attacker with remote access to bypass file‑system access controls, leading to read or write access to protected files. The vulnerability is identified as CWE‑667 and does not grant arbitrary code execution but enables the attacker to access sensitive configuration or user data. The impact is confined to confidentiality and integrity of the file system rather than system availability.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions before 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions before 5.36.00.00 are affected. These appliances provide remote VPN and connectivity services and are typically deployed in perimeter or data‑center environments.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The likely attack vector is a remote low‑privileged connection that can exploit the race condition to gain unauthorized filesystem access. The absence of a public exploit means the risk is mainly theoretical until a vulnerability is leveraged in the wild.

Generated by OpenCVE AI on September 7, 2026 at 17:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Secure Connect Gateway 5.0 Appliance to version 5.36.00.16 or later, and Upgrade Application to version 5.36.00.00 or later to obtain the vendor’s fix for the improper locking issue.
  • Restrict remote access to the appliance by enforcing strict authentication, role‑based access control, and network segmentation to reduce the attack surface for low‑privileged users.
  • Implement monitoring and logging for file‑system access events to detect any unauthorized read or write activity that could indicate exploitation of the unlocking race.

Generated by OpenCVE AI on September 7, 2026 at 17:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Locking Enables File System Access in Dell Secure Connect Gateway 5.0

Mon, 07 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Locking vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker.
Weaknesses CWE-667
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T16:13:16.435Z

Reserved: 2026-08-25T20:04:12.994Z

Link: CVE-2026-80126

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T17:17:25.450

Modified: 2026-09-07T17:17:25.450

Link: CVE-2026-80126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T17:45:17Z

Weaknesses