Executive brief
Dell Secure Connect Gateway (SCG) is a network security appliance that manages remote access for enterprise organizations. A low-privileged local attacker can inject arbitrary operating system commands through improper input validation, potentially executing arbitrary code with elevated privileges on the gateway.
Technical details
The vulnerability is an OS command injection flaw (CWE-78) in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. The root cause is improper neutralization of special characters in user-supplied input before passing it to an OS command execution function. Exploitation requires local access and low privilege credentials. A successful exploit allows the attacker to execute arbitrary commands on the host system, potentially achieving full system compromise. Patches are available in version 5.36.00.16 (Appliance) and 5.36.00.00 (Application).
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed: Advisory published by Dell (DSA-2026-382)
- 2026-09-09: patched: Patches available: Appliance 5.36.00.16, Application 5.36.00.00