Executive brief
Dell Secure Connect Gateway (SCG) is a secure remote access appliance used to manage and control corporate network connections. A vulnerability in SCG allows a low-privileged local user to elevate their privileges to higher levels without proper authorization, potentially gaining administrative control of the system and access to sensitive corporate data.
Technical details
This is an Improper Privilege Management vulnerability (CWE-269) in Dell SCG 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00 respectively. The vulnerability allows an authenticated local attacker with low privileges to escalate to higher privilege levels due to inadequate privilege validation. The attack vector is local and requires prior authentication (PR:L), but no user interaction. An attacker can achieve elevation of privileges to gain unauthorized access to system resources and functionality. Patches are available in versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application).
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed: Published as CVE-2026-80166
- 2026-09-07: patched: Patch available: SCG 5.0 Appliance 5.36.00.16, SCG 5.0 Application 5.36.00.00