Executive brief
Dell Secure Connect Gateway (SCG) is a VPN and remote access solution used by enterprises to securely connect to corporate networks. Versions prior to 5.36.00.16 contain a path traversal flaw that allows unauthenticated remote attackers to read or write files outside intended directories, potentially leading to remote code execution and complete system compromise.
Technical details
The vulnerability is a path traversal (CWE-22) in Dell SCG that improperly validates pathname restrictions, allowing directory traversal attacks. An unauthenticated attacker with network access to the appliance or application can craft requests with path traversal sequences (e.g., "../" patterns) to access files outside the restricted directory. This can enable reading sensitive configuration files or writing malicious files to locations executable by the application process, achieving remote code execution without authentication. Patches are available in Dell SCG 5.36.00.16 (Appliance) and 5.36.00.00 (Application).
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed