Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Published: 2026-09-07
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Improper Authentication flaw in Dell Secure Connect Gateway 5.0 allows a remote attacker with low privileges to bypass protection mechanisms, potentially enabling unauthorized access to the appliance or application. The weakness is categorized as CWE‑287 and could compromise confidentiality, integrity, or availability if exploited. The description indicates that the attacker does not need privileged credentials but can leverage remote reachability to undermine the system’s authentication safeguards.

Affected Systems

This vulnerability affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. The affected products are the Appliance and Application components of the Secure Connect Gateway suite.

Risk and Exploitability

The CVSS score of 6.4 reflects a moderate severity. EPSS data is unavailable, so exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote access by an attacker with low privileged credentials, which could lead to protection mechanism bypass if the vulnerability is successfully leveraged. The overall risk is moderate, but the absence of a KEV listing or EPSS score does not negate the need for timely remediation.

Generated by OpenCVE AI on September 7, 2026 at 14:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install Dell Security Update DSA-2026-382 for Secure Connect Gateway from Dell support.
  • Ensure appliance and application versions are updated to 5.36.00.16 or later for appliance and 5.36.00.00 or later for application.
  • Restrict remote access to the appliance by configuring firewall or VPN to limit connections to authorized users.

Generated by OpenCVE AI on September 7, 2026 at 14:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T13:40:26.531Z

Reserved: 2026-08-25T20:04:12.994Z

Link: CVE-2026-80128

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T14:16:54.580

Modified: 2026-09-07T14:16:54.580

Link: CVE-2026-80128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:45:17Z

Weaknesses