Executive brief
Dell Secure Connect Gateway (SCG) is a remote access and VPN appliance used by organizations to enable secure connectivity. A race condition vulnerability in versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) allows an unauthenticated attacker to trigger a denial of service, potentially disrupting access for legitimate users.
Technical details
CVE-2026-79968 is a Time-of-Check Time-of-Use (TOCTOU) race condition in Dell SCG 5.0. The vulnerability exists in versions prior to Appliance 5.36.00.16 and Application 5.36.00.00. An unauthenticated attacker with network access can exploit the race condition window between a security check and the actual use of a resource to cause denial of service. The vulnerability requires no special privileges or user interaction. Patches are available in the identified fixed versions.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed