Description
ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-07
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Patch Now
AI Analysis

Impact

This flaw is a missing authentication vulnerability affecting critical functions in Dell Secure Connect Gateway 5.0. An unauthenticated attacker with remote access could potentially exploit the flaw to gain unauthorized access to the appliance or application, compromising control over the device. The vulnerability is rated with a CVSS score of 8.1.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are affected.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity and the lack of an EPSS score means a precise exploitation probability is unknown. The vulnerability is not listed in CISA KEV. The attack vector is remote and requires no authentication, so any host with network connectivity to the appliance or application could be targeted. Organizations that run legacy deployments without the update are at risk of exposure.

Generated by OpenCVE AI on September 7, 2026 at 14:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway 5.0 security update as outlined in the Dell KB doc (upgrade to 5.36.00.16 for Appliances and 5.36.00.00 for Applications).
  • If the update cannot be applied immediately, restrict or disable remote access to the appliance or application to trusted IP ranges.
  • Enforce strong authentication on all administrative functions, including changing default credentials and configuring MFA where available.

Generated by OpenCVE AI on September 7, 2026 at 14:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell secure Connect Gateway

Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application
Vendors & Products Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Remote Unauthorized Access via Missing Authentication in Dell Secure Connect Gateway 5.0

Mon, 07 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Secure Connect Gateway Secure Connect Gateway Appliance Secure Connect Gateway Application
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-08T16:55:35.760Z

Reserved: 2026-08-25T20:04:12.994Z

Link: CVE-2026-80132

cve-icon Vulnrichment

Updated: 2026-09-08T16:41:12.967Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T13:20:38.670

Modified: 2026-09-11T21:25:41.970

Link: CVE-2026-80132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:37:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function