Executive brief
Dell Secure Connect Gateway (SCG) is a network appliance and application that provides secure remote access and connectivity for enterprise environments. A race condition vulnerability in shared resource handling allows an unauthenticated attacker with network access to crash or degrade the service, causing a denial of service to legitimate users.
Technical details
The vulnerability is a concurrent execution race condition (CWE-362) involving improper synchronization of shared resources in Dell SCG 5.0. An unauthenticated attacker with remote network access can trigger the race condition by sending specially crafted requests that exploit timing windows in shared resource access. The vulnerability does not require authentication or user interaction, making it network-exploitable. Successful exploitation leads to denial of service conditions. Patches are available: SCG 5.0 Appliance should be updated to version 5.36.00.16 or later, and SCG 5.0 Application should be updated to version 5.36.00.00 or later.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Patches released: SCG 5.0 Appliance 5.36.00.16, SCG 5.0 Application 5.36.00.00