Executive brief
Dell Secure Connect Gateway (SCG) is a remote access appliance and application used to provide secure connectivity to enterprise networks. Versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) contain a relative path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files or potentially execute code on the system, potentially compromising network access and sensitive data.
Technical details
The vulnerability is a relative path traversal flaw in Dell SCG 5.0 that permits an unauthenticated attacker with network access to traverse directory structures and access files outside intended boundaries. The vulnerability class is CWE-23 (Relative Path Traversal). Since the advisory notes that exploitation could lead to remote execution and the attack requires no authentication or user interaction, the attack vector is network-based. An attacker can exploit this by crafting malicious requests with path traversal sequences (e.g., ../ patterns) to access sensitive configuration files, credentials, or executable code. Dell has released patches in versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application) to remediate this issue.
Affected products
- Dell Secure Connect Gateway Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed: CVE-2026-80133 disclosed; Dell advisory DSA-2026-382 published
- 2026-09-07: patched: Patches available: SCG Appliance 5.36.00.16 and later, SCG Application 5.36.00.00 and later