Executive brief
Dell Secure Connect Gateway (SCG) is a critical network security appliance and application used to manage secure remote access to corporate networks. Versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) contain an improper authentication vulnerability that allows remote attackers with low privileges to bypass security controls, potentially gaining unauthorized access to protected systems and data.
Technical details
The vulnerability is an improper authentication flaw in Dell SCG 5.0 that fails to properly validate credentials or session tokens. A low-privileged attacker with network access can exploit this weakness to bypass authentication mechanisms and protection controls. The vulnerability is remotely exploitable without requiring special network conditions (low complexity). Successful exploitation could lead to unauthorized access and manipulation of the gateway's security functions, though the advisory indicates a medium severity with CVSS score of 6.4. Patches are available in Dell SCG 5.0 Appliance version 5.36.00.16 and Application version 5.36.00.00.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed