Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Published: 2026-09-07
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 Appliance and Application versions before 5.36.00.16 and 5.36.00.00 respectively expose an Improper Limitation of a Pathname to a Restricted Directory vulnerability (Path Traversal). The flaw enables an unauthenticated attacker acting over a remote connection to read or write arbitrary files by manipulating path names. If successful, the attacker could inject malicious code or gain control of the system, thereby compromising confidentiality, integrity, and availability of the gateway services.

Affected Systems

The vulnerability is present in Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and in the Dell Secure Connect Gateway 5.0 Application before 5.36.00.00. Only these versions are impacted; newer releases are not affected.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, but the possibility of remote code execution qualifies it as a serious risk. An attacker does not need authentication, so the likelihood of successful exploitation in a connected environment is high. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog; however, the remote nature and potential for arbitrary code execution warrant prompt action. Based on the description, the attack vector involves remote network access to the gateway, likely via exposed management interfaces or services.

Generated by OpenCVE AI on September 7, 2026 at 14:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the appliance to v5.36.00.16 or later, and upgrade the application to v5.36.00.00 or later, as these versions contain the fix for the path traversal flaw.
  • If an immediate upgrade is not possible, isolate the Secure Connect Gateway from untrusted networks and restrict remote management access to only trusted IP addresses to reduce exposure.
  • As a temporary mitigation, disable any services that allow file upload or path manipulation on the gateway until the patch can be applied.

Generated by OpenCVE AI on September 7, 2026 at 14:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Path Traversal Allowing Remote Execution in Dell Secure Connect Gateway

Mon, 07 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T13:28:38.676Z

Reserved: 2026-08-25T20:04:12.994Z

Link: CVE-2026-80129

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T14:16:54.697

Modified: 2026-09-07T14:16:54.697

Link: CVE-2026-80129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:45:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')