Executive brief
Dell Secure Connect Gateway (SCG) is a secure remote access appliance and application used by organizations to protect network connectivity. A timing-based race condition vulnerability allows unauthenticated remote attackers to exploit concurrent operations, potentially causing service disruptions and denial of service on the gateway.
Technical details
CVE-2026-79730 is a Time-of-check Time-of-use (TOCTOU) race condition in Dell SCG 5.0 Appliance (prior to 5.36.00.16) and Application (prior to 5.36.00.00). The vulnerability allows an unauthenticated attacker with network access to exploit a timing gap between a security check and a subsequent operation, leading to denial of service. No authentication is required to trigger the condition, and the attack can be performed remotely over the network. The vulnerability results in availability impact through service disruption. Dell has released patches in versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application).
Affected products
- Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
- Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Appliance 5.36.00.16, Application 5.36.00.00