GBHackers

Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access


Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities.

These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise.

Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions earlier than 5.36.00.00.

Dell strongly urges affected organizations to upgrade immediately, citing the severity of these vulnerabilities and the risk of complete compromise of exposed gateways.

Dell Secure Connect Gateway Critical Flaws

The first issue, CVE-2026-80172, is rated 9.8 under CVSS v3.1 and involves insufficient verification of data authenticity. According to Dell, a remote, unauthenticated attacker could repeatedly replay a captured request to gain ADMIN access and refresh tokens.

The request-handling process lacks nonce validation and a time limit, allowing replay attempts to continue indefinitely. This vulnerability requires no privileges or user interaction.

It affects confidentiality, integrity, and availability, making it particularly dangerous when SCG interfaces are accessible from untrusted networks.

The second issue, CVE-2026-61410, has a CVSS score of 9.4 and arises from missing authorization. Dell states that an unauthenticated remote attacker can send a specially crafted request to the application, bypass intended restrictions on code execution, and execute commands on the target system.

Successful exploitation could give the intruder direct access to a support-management platform, which often contains valuable operational data and privileged connectivity.

While the impact on availability is rated low, the potential for high confidentiality and integrity impact, along with the ability to execute remote commands, allows for follow-on actions such as credential theft, persistence, lateral movement, or data exfiltration.

The third issue, CVE-2026-80238, carries a score of 9.3 and concerns execution with unnecessary privileges. The advisory describes an exposed Docker socket that allows a low-privileged operator with SSH access to obtain root-level access to the SCG host without a password.

Dell also warns that compromising a service within the orchestrator container could provide access to the same socket, leading to container escape and host takeover.

Although this risk requires local access, it significantly increases the potential post-compromise risk. It can turn limited access into total control of the appliance.

Secure Connect Gateway is designed to centralize monitoring and support connectivity. Therefore, treat these vulnerabilities as potentially high-impact infrastructure exposures.

Organizations should inventory both appliance and application installations, confirm their exact versions, and upgrade to the remediated versions specified by Dell.

Administrators should also review internet exposure, restrict management interfaces to trusted networks, rotate credentials and tokens when compromise is suspected, and examine logs for unusual requests, unexpected administrative sessions, command execution, or container-related activity.

Organizations must prioritize these updates, as the two remote flaws require neither authentication nor user interaction. If upgrades cannot be performed, isolating SCG systems, limiting access paths, and monitoring for exploitation may help reduce exposure. However, these measures are not substitutes for Dell’s fixes.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection



Source link