Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Published: 2026-09-07
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a Relative Path Traversal flaw that allows an unauthenticated attacker with remote access to construct file paths that reference system files. Exploitation can lead to arbitrary code execution on the affected system. This weakness aligns with CWE-23, a well-known weakness that can compromise confidentiality, integrity, and availability.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00 are vulnerable.

Risk and Exploitability

The CVSS score of 7.4 indicates a medium to high severity. EPSS data is missing, so the current exploitation likelihood is unclear, but the lack of a KEV listing suggests no documented active exploitation yet. The likely attack vector is remote, unauthenticated access, meaning any host that can reach the gateway over the network could attempt the exploit.

Generated by OpenCVE AI on September 7, 2026 at 14:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell patch 5.36.00.16 or later to the Secure Connect Gateway 5.0 Appliance and patch 5.36.00.00 or later to the Application.
  • Restrict or disable remote management access to the gateway, using firewall rules or network segmentation to limit exposure to trusted hosts only.
  • Continuously monitor access logs for anomalous path traversal attempts or unexpected file execution events.

Generated by OpenCVE AI on September 7, 2026 at 14:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell secure Connect Gateway

Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application
Vendors & Products Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Path Traversal in Dell Secure Connect Gateway 5.0 Leading to Remote Execution

Mon, 07 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Dell Secure Connect Gateway Secure Connect Gateway Appliance Secure Connect Gateway Application
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-08T13:51:57.095Z

Reserved: 2026-08-25T20:04:12.994Z

Link: CVE-2026-80133

cve-icon Vulnrichment

Updated: 2026-09-08T13:51:50.498Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T13:20:38.800

Modified: 2026-09-11T21:25:32.910

Link: CVE-2026-80133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:37:14Z

Weaknesses
  • CWE-23

    Relative Path Traversal