Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
Published: 2026-09-07
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Privilege Management flaw that allows an unauthenticated attacker with local access to elevate privileges on Dell Secure Connect Gateway 5.0 Appliance and Application. This flaw is classified as CWE-269 and can enable the attacker to gain administrative or higher rights, leading to potential system compromise or additional attacks. The impact is local privilege escalation which, if combined with other vulnerabilities, may permit full control over the device.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions prior to 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions prior to 5.36.00.00 are impacted. The vulnerable software is provided as an appliance or application bundle from Dell and is commonly deployed in corporate VPN or remote access environments.

Risk and Exploitability

The vulnerability has a CVSS score of 7.8 indicating high severity. No EPSS data is available and it is not listed in the CISA KEV catalog, suggesting no known public exploitation has been observed. The likely attack vector requires local, unauthenticated access, meaning the attacker must have local network presence to the device for exploitation. While this limits exposure to environments where local access is possible, the high severity and privilege escalation potential warrant prompt remediation.

Generated by OpenCVE AI on September 7, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Dell SCG 5.0 security update to Appliance version 5.36.00.16 or newer, and Application version 5.36.00.00 or newer, as published in the Dell support advisory.
  • Restrict local network access to the Secure Connect Gateway appliance and application until the update is applied to mitigate potential exploitation.
  • Enforce strong, role‑based authentication on all local interfaces and disable any default or unused privileged accounts to reduce the impact of privilege escalation.

Generated by OpenCVE AI on September 7, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Privilege Management in Dell Secure Connect Gateway 5.0

Mon, 07 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T16:36:37.437Z

Reserved: 2026-08-25T21:04:22.134Z

Link: CVE-2026-80166

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T17:17:25.570

Modified: 2026-09-07T17:17:25.570

Link: CVE-2026-80166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T17:30:06Z

Weaknesses
  • CWE-269

    Improper Privilege Management