Dell Secure Connect Gateway vulnerabilities
98 known vulnerabilities affecting dell/secure_connect_gateway.
Total CVEs
98
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH29MEDIUM50LOW13
Vulnerabilities
Page 3 of 5
CVE-2026-79974P3MEDIUMCVSS 6.4fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79974 [MEDIUM] CWE-287 CVE-2026-79974: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
nvd
CVE-2026-79741P3MEDIUMCVSS 5.3fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79741 [MEDIUM] CWE-77 CVE-2026-79741: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.
nvd
CVE-2024-47240P3MEDIUMCVSS 6.3v5.24.00.142024-10-18
CVE-2024-47240 [MEDIUM] CWE-276 CVE-2024-47240: Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A lo
Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A local attacker with low privileges can access the file system and could potentially exploit this vulnerability to gain write access to unauthorized data and cause a version update failure condition.
nvd
CVE-2026-79973P3MEDIUMCVSS 6.3fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79973 [MEDIUM] CWE-567 CVE-2026-79973: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Unsynchronized Access to Shared Data in a Multithreaded Context vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2023-44294P3MEDIUMCVSS 6.5≥ 5.10.00.00, < 5.20.00.002024-02-14
CVE-2023-44294 [MEDIUM] CWE-89 CVE-2023-44294: In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.0
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of Collection Rest API.
This issue may potentially lead to unintentional information disclosure from the
nvd
CVE-2023-44293P3MEDIUMCVSS 6.5≥ 5.10.00.00, < 5.20.00.002024-02-14
CVE-2023-44293 [MEDIUM] CWE-89 CVE-2023-44293: In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.0
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the pr
nvd
CVE-2026-79947P3MEDIUMCVSS 5.5fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79947 [MEDIUM] CWE-89 CVE-2026-79947: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to script injection.
nvd
CVE-2026-78489P4MEDIUMCVSS 5.9fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-78489 [MEDIUM] CWE-295 CVE-2026-78489: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
nvd
CVE-2026-78483P4MEDIUMCVSS 5.9fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-78483 [MEDIUM] CWE-295 CVE-2026-78483: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
nvd
CVE-2023-28043P4MEDIUMCVSS 6.5v5.14.00.162023-06-01
CVE-2023-28043 [MEDIUM] CWE-327 CVE-2023-28043: Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path.
Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerability to retrieve the plain text.
nvd
CVE-2026-79967P4MEDIUMCVSS 5.6fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79967 [MEDIUM] CWE-295 CVE-2026-79967: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
nvd
CVE-2026-79640P4MEDIUMCVSS 5.4fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79640 [MEDIUM] CWE-89 CVE-2026-79640: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
nvd
CVE-2026-79970P4MEDIUMCVSS 5.6fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79970 [MEDIUM] CWE-347 CVE-2026-79970: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
nvd
CVE-2026-79961P4MEDIUMCVSS 5.3fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79961 [MEDIUM] CWE-306 CVE-2026-79961: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
nvd
CVE-2026-79730P4MEDIUMCVSS 5.6fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79730 [MEDIUM] CWE-367 CVE-2026-79730: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2024-28968P4MEDIUMCVSS 5.4≥ 5.18.00.20, ≤ 5.22.00.182024-06-13
CVE-2024-28968 [MEDIUM] CWE-284 CVE-2024-28968: Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for internal email and collection settings REST APIs (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on
nvd
CVE-2024-28965P4MEDIUMCVSS 5.4≥ 5.18.00.20, ≤ 5.22.00.182024-06-13
CVE-2024-28965 [MEDIUM] CWE-284 CVE-2024-28965: Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain Internal APIs applicable only for Admin Users on the applicat
nvd
CVE-2024-28966P4MEDIUMCVSS 5.4≥ 5.18.00.20, ≤ 5.22.00.182024-06-13
CVE-2024-28966 [MEDIUM] CWE-284 CVE-2024-28966: Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's bac
nvd
CVE-2024-28967P4MEDIUMCVSS 5.4≥ 5.18.00.20, ≤ 5.22.00.182024-06-13
CVE-2024-28967 [MEDIUM] CWE-284 CVE-2024-28967: Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application'
nvd
CVE-2025-46696P4MEDIUMCVSS 6.7≥ 5.26.00.00, < 5.32.00.002026-01-06
CVE-2025-46696 [MEDIUM] CWE-250 CVE-2025-46696: Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, c
Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
nvd