
[CIVN-2026-0449] Multiple Vulnerabilities in Dell Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Dell Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16
Dell Secure Connect Gateway (SCG) 5.0 Application versions prior to 5.36.00.00
Overview
Multiple vulnerabilities have been reported in Dell Secure Connect Gateway Application and Appliance which may allow an attacker to gain unauthorized access, execute commands remotely, bypass security mechanisms, gain elevated privileges, disclose sensitive information, access restricted files or directories, or cause denial of service (DoS) condition on the targeted system.
Target Audience:
Individuals and organizations using the above-mentioned Dell products.
Risk Assessment:
High risk of unauthorized access, arbitrary code execution, privilege escalation, security mechanism bypass, sensitive information disclosure, system compromise.
Impact Assessment:
Potential for remote code execution, exposure of credentials and sensitive information, filesystem access, security mechanism bypass, disruption of services, compromise of the affected system.
Description
Dell Secure Connect Gateway (SCG) is a Dell solution that provides connectivity and support capabilities for Dell infrastructure.
These vulnerabilities exist in in Dell Secure Connect Gateway Application and Appliance due to insufficient verification of data authenticity, missing authentication and authorization, improper certificate validation, improper privilege management, use of hard-coded credentials and cryptographic keys, OS command injection, SQL injection, path traversal, server-side request forgery (SSRF), improper handling of highly compressed data, improper authentication, race conditions, and other security weaknesses.
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access, execute commands remotely, bypass security mechanisms, gain elevated privileges, disclose sensitive information, access restricted files or directories, or cause denial of service (DoS) condition on the targeted system.
Solution
Apply appropriate updates as mentioned in:
https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities
Vendor Information
Dell
https://www.dell.com/
References
https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities
CVE Name
CVE-2026-80172
CVE-2026-61410
CVE-2026-80238
CVE-2026-79645
CVE-2026-78491
CVE-2026-80132
CVE-2026-80166
CVE-2026-79637
CVE-2026-80134
CVE-2026-79639
CVE-2026-80135
CVE-2026-79738
CVE-2026-79740
CVE-2026-78490
CVE-2026-79950
CVE-2026-78480
CVE-2026-79641
CVE-2026-78492
CVE-2026-80131
CVE-2026-80164
CVE-2026-78494
CVE-2026-79963
CVE-2026-79644
CVE-2026-79692
CVE-2026-80123
CVE-2026-79643
CVE-2026-79635
CVE-2026-80122
CVE-2026-79691
CVE-2026-79695
CVE-2026-61409
CVE-2026-78485
CVE-2026-79972
CVE-2026-80127
CVE-2026-80130
CVE-2026-79636
CVE-2026-78482
CVE-2026-80170
CVE-2026-80177
CVE-2026-78488
CVE-2026-78481
CVE-2026-79728
CVE-2026-80129
CVE-2026-80126
CVE-2026-61408
CVE-2026-79974
CVE-2026-80128
CVE-2026-79973
CVE-2026-78483
CVE-2026-78489
CVE-2026-79734
CVE-2026-80125
CVE-2026-79967
CVE-2026-79970
CVE-2026-79642
CVE-2026-79968
CVE-2026-79730
CVE-2026-78484
CVE-2026-79975
CVE-2026-80124
CVE-2026-80167
CVE-2026-80054
CVE-2026-80056
CVE-2026-80178
CVE-2026-79947
CVE-2026-79945
CVE-2026-80057
CVE-2026-80058
CVE-2026-79694
CVE-2026-79640
CVE-2026-80174
CVE-2026-79964
CVE-2026-79638
CVE-2026-79962
CVE-2026-79969
CVE-2026-79969
CVE-2026-79971
CVE-2026-79741
CVE-2026-79941
CVE-2026-79946
CVE-2026-79961
CVE-2026-79952
CVE-2026-79965
CVE-2026-79943
CVE-2026-80176
CVE-2026-80171
CVE-2026-78486
CVE-2026-78486
CVE-2026-79736
CVE-2026-79729
CVE-2026-79690
CVE-2026-79732
CVE-2026-79944
CVE-2026-79693
CVE-2026-79942
CVE-2026-80169
CVE-2026-80175
CVE-2026-79727
CVE-2026-79966
CVE-2026-79966
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqiwasACgkQ3jCgcSdc
ys/uwQ//bYHIOppMjP9Cgax6wAyLc7BgNWvMyr/Yk61+wy8jAKc4WZRIgWpU4mxD
cY9A6mCe5Jga6E1GEU0zf7CUiH7xLT21V0DNvKjabFY+xcMfxqx90wM+izx0TBOf
W6Yy/OFEr8XFG+ieDmzfbz3uA8A9f+74IT3wG5vsazo4MCQo7KmipqJ1hyTD/FkT
ja8Q583/f/2E+gpZ0s3SbDz19I+BGxeTwIGv8PA1yvtbDshhwfxyyogNve2gtUYP
WOmampw7O0BAS/n4akK9CJ78pXY9UEPlvfuaszNr1XXnMfE2mwGQvngegb35EDiA
roqO240ePR1uys3m3gFDW01r6bxdxi46KqCCMdELy/zClEWlgKMIyjIfFAnSvV3R
jkGDBy/N3nvnWO+VQ4mKopV4IOsGH2E7H515XBds+UO75H94v/xwEVj2KiDzjoXA
vQBWXNUWhIXNPXqBPuAHhOiJwF3ftnZWk3330HXbmgXX/sOlzIpmpWmZeMuFUAL7
qgWIIfdW2AHdnQXQg8fiBN2yZtjOywRCTR2WtNhR/oCTXs0Fbgw0MyRITA/BU4k5
rBSIGXOvXVM1xOXTGqJmQE05OqG59u4XaZqTbxEzyMxCraOY5D1Mmd1ZrVMAHzQu
xqp9LTeImBaY2daOuB8KO3CIYKeRZtWCrn8s+Y3rqz5LnstD1tg=
=gpr+
—–END PGP SIGNATURE—–


