Executive brief
Dell Secure Connect Gateway (SCG) is a network appliance and application used for secure remote access and connectivity. A race condition vulnerability in the multithreaded components allows a remote attacker with low privileges to cause a denial of service by exploiting unsynchronized access to shared data, disrupting availability of the gateway for legitimate users.
Technical details
This vulnerability is a race condition (CWE-366: Unsynchronized Access to Shared Data in a Multithreaded Context) affecting Dell SCG 5.0 components. The root cause is improper synchronization of shared data structures accessed by multiple threads, allowing concurrent access without proper locking mechanisms. A low-privileged remote attacker can exploit this by sending specially crafted requests that trigger unsynchronized data access, causing a denial of service condition. The vulnerability requires network reachability and low-privilege credentials. Patches are available in SCG 5.0 Appliance version 5.36.00.16 and SCG 5.0 Application version 5.36.00.00 or later.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed