Junglewise Threat Intelligence

CVE-2026-79973: Dell Secure Connect Gateway race condition in multithreaded context

CVE-2026-79973 · Severity: medium · CVSS 6.3 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a network appliance and application used for secure remote access and connectivity. A race condition vulnerability in the multithreaded components allows a remote attacker with low privileges to cause a denial of service by exploiting unsynchronized access to shared data, disrupting availability of the gateway for legitimate users.

Technical details

This vulnerability is a race condition (CWE-366: Unsynchronized Access to Shared Data in a Multithreaded Context) affecting Dell SCG 5.0 components. The root cause is improper synchronization of shared data structures accessed by multiple threads, allowing concurrent access without proper locking mechanisms. A low-privileged remote attacker can exploit this by sending specially crafted requests that trigger unsynchronized data access, causing a denial of service condition. The vulnerability requires network reachability and low-privilege credentials. Patches are available in SCG 5.0 Appliance version 5.36.00.16 and SCG 5.0 Application version 5.36.00.00 or later.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed

References

Related threats