Dell Secure Connect Gateway vulnerabilities
98 known vulnerabilities affecting dell/secure_connect_gateway.
Total CVEs
98
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH29MEDIUM50LOW13
Vulnerabilities
Page 4 of 5
CVE-2023-23695P4MEDIUMCVSS 5.9v5.12.00.10v5.14.00.122023-02-17
CVE-2023-23695 [MEDIUM] CWE-327 CVE-2023-23695: Dell Secure Connect Gateway (SCG) version 5.14.00.12 contains a broken cryptographic algorithm vuln
Dell Secure Connect Gateway (SCG) version 5.14.00.12 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information.
nvd
CVE-2026-79969P4MEDIUMCVSS 5.9fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79969 [MEDIUM] CWE-567 CVE-2026-79969: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2026-79962P4MEDIUMCVSS 5.9fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79962 [MEDIUM] CWE-567 CVE-2026-79962: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2026-79952P4MEDIUMCVSS 5.3fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79952 [MEDIUM] CWE-116 CVE-2026-79952: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Encoding or Escaping of Output vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to launch of phishing attacks.
nvd
CVE-2026-79965P4MEDIUMCVSS 5.3fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79965 [MEDIUM] CWE-625 CVE-2026-79965: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control of Critical State Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
nvd
CVE-2026-80174P4MEDIUMCVSS 5.3fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-80174 [MEDIUM] CWE-613 CVE-2026-80174: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to session theft.
nvd
CVE-2026-79968P4MEDIUMCVSS 5.9fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79968 [MEDIUM] CWE-367 CVE-2026-79968: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2026-79971P4MEDIUMCVSS 5.3fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79971 [MEDIUM] CWE-1236 CVE-2026-79971: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Sanitization of Custom Special Characters vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.
nvd
CVE-2026-79946P4MEDIUMCVSS 5.3fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79946 [MEDIUM] CWE-87 CVE-2026-79946: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.
nvd
CVE-2026-79964P4MEDIUMCVSS 5.3fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79964 [MEDIUM] CWE-116 CVE-2026-79964: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Escape, Meta, or Control Sequences vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to launch of phishing attacks.
nvd
CVE-2026-79638P4MEDIUMCVSS 5.3fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79638 [MEDIUM] CWE-693 CVE-2026-79638: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.
nvd
CVE-2025-23382P4MEDIUMCVSS 5.8v5.26.00.202025-03-19
CVE-2025-23382 [MEDIUM] CWE-497 CVE-2025-23382: Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of Se
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.c
nvd
CVE-2024-22458P4MEDIUMCVSS 5.3v5.18.00.20v5.20.00.102024-03-01
CVE-2024-22458 [MEDIUM] CWE-327 CVE-2024-22458: Dell Secure Connect Gateway, 5.18, contains an Inadequate Encryption Strength Vulnerability. An unau
Dell Secure Connect Gateway, 5.18, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, allowing an attacker to recover plaintext from a block of ciphertext.
nvd
CVE-2025-26475P4MEDIUMCVSS 5.5v5.26.00.202025-03-19
CVE-2025-26475 [MEDIUM] CWE-287 CVE-2025-26475: Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances security by keeping containers running during daemon restarts, reducing attack exposure, preventing accidental misconfigurations, and ensuring security controls remain active.
nvd
CVE-2026-79694P4MEDIUMCVSS 5.5fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79694 [MEDIUM] CWE-215 CVE-2026-79694: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information Into Debugging Code vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
nvd
CVE-2026-80124P4MEDIUMCVSS 5.5fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-80124 [MEDIUM] CWE-532 CVE-2026-80124: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
nvd
CVE-2026-78487P4MEDIUMCVSS 5.5fixed in 5.36.00.00fixed in 5.36.00.162026-09-07
CVE-2026-78487 [MEDIUM] CWE-321 CVE-2026-78487: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2026-80055P4MEDIUMCVSS 4.4fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-80055 [MEDIUM] CWE-90 CVE-2026-80055: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.
nvd
CVE-2026-79731P4MEDIUMCVSS 4.4fixed in 5.36.00.00fixed in 5.36.00.162026-09-09
CVE-2026-79731 [MEDIUM] CWE-798 CVE-2026-79731: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.
nvd
CVE-2025-46363P4MEDIUMCVSS 4.3≥ 5.26.00.00, < 5.32.00.002025-10-30
CVE-2025-46363 [MEDIUM] CWE-23 CVE-2025-46363: Dell Secure Connect Gateway (SCG) 5.0 Application and Appliance version(s) 5.26.00.00 - 5.30.00.00,
Dell Secure Connect Gateway (SCG) 5.0 Application and Appliance version(s) 5.26.00.00 - 5.30.00.00, contain a Relative Path Traversal vulnerability in the SCG exposed for an internal collection download REST API (if this REST API is enabled by Admin user from UI). A low privileged attacker with remote access could potentially exploit this vulnerabilit
nvd