Executive brief
Dell Secure Connect Gateway (SCG) is a secure remote access appliance used by enterprises to manage VPN and secure connections. An unauthenticated remote attacker can download and execute arbitrary code on the device without integrity verification, potentially gaining complete control over the system and compromising all connected client traffic and data.
Technical details
This is a code integrity verification vulnerability in Dell SCG 5.0 versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application). The flaw allows unauthenticated remote attackers to download code or executables without integrity checks, enabling arbitrary code execution on the appliance. The attack vector is network-based and requires no authentication or user interaction. Successful exploitation grants an attacker the ability to execute arbitrary commands on the affected system. Patches are available in versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application) or later.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed