Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Published: 2026-09-07
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Relative Path Traversal flaw that allows an unauthenticated attacker with remote access to construct file paths that reference system files. Exploitation can lead to arbitrary code execution on the affected system. This weakness aligns with CWE-23, a well-known weakness that can compromise confidentiality, integrity, and availability.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are vulnerable.

Risk and Exploitability

The CVSS score of 7.4 indicates a medium to high severity. EPSS data is missing, so the current exploitation likelihood is unclear, but the lack of a KEV listing suggests no documented active exploitation yet. The likely attack vector is remote, unauthenticated access, meaning any host that can reach the gateway over the network could attempt the exploit.

Generated by OpenCVE AI on September 7, 2026 at 14:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell patch 5.36.00.16 or later to the Secure Connect Gateway 5.0 Appliance and patch 5.36.00.00 or later to the Application.
  • Restrict or disable remote management access to the gateway, using firewall rules or network segmentation to limit exposure to trusted hosts only.
  • Continuously monitor access logs for anomalous path traversal attempts or unexpected file execution events.

Generated by OpenCVE AI on September 7, 2026 at 14:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Path Traversal in Dell Secure Connect Gateway 5.0 Leading to Remote Execution

Mon, 07 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T12:36:54.891Z

Reserved: 2026-08-25T20:04:12.994Z

Link: CVE-2026-80133

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T13:20:38.800

Modified: 2026-09-07T13:20:38.800

Link: CVE-2026-80133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:15:16Z

Weaknesses
  • CWE-23

    Relative Path Traversal