Executive brief
Dell Secure Connect Gateway (SCG) is a remote access and VPN appliance used to secure enterprise network connections. An unauthenticated attacker can inject arbitrary OS commands through improper input validation, allowing them to execute code remotely and gain full control of the gateway system. This could lead to unauthorized access to protected networks, data theft, and service outages.
Technical details
The vulnerability is an OS command injection (CWE-78) caused by improper neutralization of special elements in user input before passing them to OS command execution functions. An unauthenticated, remote attacker can exploit this by crafting a malicious request containing shell metacharacters that bypass input validation. No authentication is required and the attack vector is network-accessible, making this easily exploitable. A successful exploit allows arbitrary command execution with the privileges of the gateway process, potentially leading to full system compromise. Dell released patches in versions 5.36.00.00 (Application) and 5.36.00.16 (Appliance).
Affected products
- Dell Secure Connect Gateway prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Version 5.36.00.00 and later