Executive brief
Dell Secure Connect Gateway is a critical network access control appliance used by enterprises to manage remote connections and secure gateway traffic. Versions 5.0 prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain a flaw that allows unauthenticated attackers to send specially crafted highly compressed data that, when decompressed by the system, causes excessive resource consumption and renders the service unavailable to legitimate users. This denial-of-service attack requires no authentication and can be launched remotely over the network.
Technical details
The vulnerability is a data amplification attack (improper handling of highly compressed data), where an attacker sends a small, highly compressed payload that expands to a much larger size upon decompression, consuming excessive CPU, memory, or disk resources. The affected component accepts and processes this data without proper validation or resource limits before decompression. The attack vector is network-based and requires no authentication or user interaction. An unauthenticated attacker with network access to the SCG appliance can repeatedly send these payloads to exhaust system resources and cause denial of service. Dell has released patched versions 5.36.00.16 (appliance) and 5.36.00.00 (application) to remediate this issue.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed: Public disclosure via NVD and Dell DSA-2026-382