Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.
Published: 2026-09-07
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an OS Command Injection caused by improper neutralization of special elements in command strings. A high privileged attacker who can remotely reach the device can exploit it, potentially executing arbitrary system commands and raising their privileges within the Secure Connect Gateway environment. This elevates the risk from a local issue to a significant local privilege escalation threat.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected. The issue applies to both the appliance and the application components of the product line.

Risk and Exploitability

The CVSS score of 7.2 indicates a medium‑to‑high severity impact. No EPSS score is reported, and the vulnerability is not listed in KEV, suggesting that it has not yet been widely exploited but could be a target. The likely attack vector is remote access with elevated privileges, meaning that attackers who gain remote entry could leverage the injection to gain higher privileges locally. The lack of public exploitation data means the threat is considered moderate, but the potential for privilege escalation warrants prompt remediation.

Generated by OpenCVE AI on September 7, 2026 at 17:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Secure Connect Gateway 5.0 Appliance to version 5.36.00.16 or later, and upgrade the Application component to version 5.36.00.00 or later to remove the command injection flaw.
  • Restrict remote administrative access to the gateway by limiting trusted IP ranges or requiring VPN connections, thereby reducing exposure to potential remote attackers.
  • Enable comprehensive logging and audit monitoring for command execution and privilege changes, and review logs regularly for signs of unexpected activity.

Generated by OpenCVE AI on September 7, 2026 at 17:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Command Injection Allowing Privilege Escalation in Dell Secure Connect Gateway

Mon, 07 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T15:59:45.073Z

Reserved: 2026-08-25T20:04:12.994Z

Link: CVE-2026-80127

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T16:17:29.807

Modified: 2026-09-07T16:17:29.807

Link: CVE-2026-80127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T17:45:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')