Executive brief
Dell Secure Connect Gateway (SCG) is a secure remote access appliance and application used to manage and protect network connectivity. A relative path traversal vulnerability in SCG 5.0 allows a low-privileged remote attacker to read, write, or manipulate files outside their intended directory, potentially leading to remote code execution and complete system compromise.
Technical details
The vulnerability is a relative path traversal (CWE-23) in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. A low-privileged attacker with network access can exploit this flaw by crafting requests containing directory traversal sequences (e.g., "../") to access files outside the intended application directory. The vulnerability can lead to remote code execution. The attack does not require authentication, though the attacker must have some initial access or ability to reach the vulnerable endpoint. Dell has released patches in versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application).
Affected products
- Dell Secure Connect Gateway 5.0 prior to 5.36.00.16 (Appliance) and prior to 5.36.00.00 (Application)
Timeline
- 2026-09-07: disclosed: CVE-2026-80130 published on NVD