Executive brief
Dell Secure Connect Gateway (SCG) is a gateway appliance and application used to secure remote access and connectivity. An unauthenticated remote attacker can exploit a file path traversal vulnerability to access the underlying filesystem, potentially exposing sensitive configuration files, credentials, or system data without needing valid credentials.
Technical details
This vulnerability is an external control of file name or path issue (CWE-73) in Dell SCG 5.0 Appliance versions before 5.36.00.16 and Application versions before 5.36.00.00. An unauthenticated attacker with network access can exploit this by sending a specially crafted request containing path traversal sequences (e.g., "../..") to bypass directory restrictions and access arbitrary files on the system. The vulnerability requires no authentication or user interaction. A successful exploit grants the attacker read access to the filesystem, potentially exposing sensitive system files, configuration data, or other protected resources. Dell has released patched versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application) to address this issue.
Affected products
- Dell Secure Connect Gateway Appliance 5.0 versions prior to 5.36.00.16
- Dell Secure Connect Gateway Application 5.0 versions prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Patches available: Appliance 5.36.00.16, Application 5.36.00.00