Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
Published: 2026-09-07
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

This vulnerability is an Improper Privilege Management flaw that allows a low‑privileged user with local access to elevate privileges on Dell Secure Connect Gateway 5.0. An attacker who can execute operations locally may gain higher privileges, potentially taking full control of the appliance or application.

Affected Systems

The affected products are Dell Secure Connect Gateway 5.0 Appliance and 5.0 Application. Versions prior to 5.36.00.16 for the Appliance and prior to 5.36.00.00 for the Application contain the vulnerability.

Risk and Exploitability

The CVSS score of 5.5 indicates a medium severity, and because the EPSS score is not available, the exact exploitation probability cannot be determined; however, the vulnerability is not currently listed in the CISA KEV catalog. A low‑privileged attacker who can access the system locally can exploit the flaw to gain elevated privileges, enabling them to move laterally or perform other malicious actions on the compromised device.

Generated by OpenCVE AI on September 7, 2026 at 14:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Secure Connect Gateway 5.0 update (DSA‑2026‑382) to reach at least version 5.36.00.16 for the Appliance or 5.36.00.00 for the Application
  • If an update cannot be applied immediately, restrict local access to only trusted privileged users and enforce strict access controls
  • Continuously monitor for unauthorized privilege escalation attempts and audit system logs

Generated by OpenCVE AI on September 7, 2026 at 14:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell secure Connect Gateway

Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application
Vendors & Products Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Dell Secure Connect Gateway 5.0

Mon, 07 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway Secure Connect Gateway Appliance Secure Connect Gateway Application
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-08T16:55:27.755Z

Reserved: 2026-08-25T21:04:22.135Z

Link: CVE-2026-80178

cve-icon Vulnrichment

Updated: 2026-09-08T16:37:11.544Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T13:20:39.170

Modified: 2026-09-11T21:23:49.013

Link: CVE-2026-80178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:37:06Z

Weaknesses
  • CWE-269

    Improper Privilege Management