Executive brief
Dell Secure Connect Gateway (SCG) is a remote access appliance and software application used to manage secure network connections. Versions prior to 5.36.00.16 contain a server-side request forgery vulnerability that allows unauthenticated remote attackers to make unauthorized network requests through the gateway, potentially accessing internal systems and exposing sensitive data.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) flaw in Dell SCG 5.0 Appliance (prior to 5.36.00.16) and Application (prior to 5.36.00.00). An unauthenticated attacker with network access can exploit this to force the appliance to make arbitrary outbound HTTP/HTTPS requests, potentially accessing internal resources, metadata services, or other restricted endpoints. No authentication is required and the attack is network-accessible. The vulnerability can lead to unauthorized access to internal systems and services. Patches are available in version 5.36.00.16 for the appliance and 5.36.00.00 for the application.
Affected products
- Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00
- Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
Timeline
- 2026-09-09: disclosed