Executive brief
Dell Secure Connect Gateway (SCG) is a secure remote access appliance used by enterprises to enable safe connectivity for employees and partners. This SQL injection vulnerability allows a low-privileged attacker with network access to manipulate database queries and potentially extract sensitive data, modify configurations, or inject malicious scripts into the system.
Technical details
CVE-2026-80177 is a SQL injection vulnerability in Dell SCG 5.0 that stems from improper neutralization of special elements in SQL commands. The vulnerability affects both the Appliance (versions prior to 5.36.00.16) and Application (versions prior to 5.36.00.00) components. A low-privileged attacker with remote network access can exploit this by sending specially crafted requests containing SQL metacharacters to bypass query logic and execute arbitrary SQL, potentially leading to script injection and unauthorized data access. Patches are available in SCG 5.0 Appliance version 5.36.00.16 and Application version 5.36.00.00.
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-09: disclosed