Executive brief
Dell Secure Connect Gateway (SCG) is a network appliance and application that securely connects remote systems to corporate networks. A relative path traversal vulnerability in SCG allows an unauthenticated attacker with network access to read arbitrary files from the system's filesystem, potentially exposing sensitive configuration data, credentials, and other protected information.
Technical details
The vulnerability is a relative path traversal flaw in Dell SCG 5.0 versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application). An unauthenticated attacker can craft requests using path traversal sequences (e.g., "../" or equivalent relative path manipulation) to access files outside the intended directory structure. No authentication is required; the attack is entirely network-reachable. Successful exploitation grants an attacker arbitrary filesystem read access, enabling them to retrieve sensitive files including credentials, configuration data, and other protected information. The vendor has released patches (5.36.00.16 for Appliance and 5.36.00.00 for Application).
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed: Vulnerability published via Dell DSA-2026-382