Sceawere
Vulnerability Detail
CVE-2026-79645UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Missing Authentication Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 3h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- Attack Type
- CWE-306: Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-09-07T15:17:32.033Z",
"pubdate": "2026-09-07T15:17:32.033Z",
"executiveSummary": "This vulnerability involves a Missing Authentication for Critical Function within Dell SCG 5.0 Appliance and Application editions.\nThe flaw stems from a failure to enforce authentication controls on sensitive internal interfaces, allowing unauthenticated remote actors to bypass security gates.\nAffected products include Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00.\nThe primary impact is unauthorized access to the application, which could lead to full system compromise, information disclosure, or manipulation of gateway functions.\nSuccessful exploitation requires no prior authentication, meaning an attacker with network access to the appliance can interact with restricted functionalities directly.\nDue to the lack of verification mechanisms, this represents a significant security risk, effectively negating the boundary protections intended to guard critical management operations.",
"technicalDetails": "The vulnerability is categorized as a Missing Authentication for Critical Function, manifesting within the communication and management interfaces of the Dell SCG platform.\nThe root cause of this security defect is the absence of an integrated authentication check within specific API endpoints or internal routines responsible for executing critical administrative or system tasks. In a secure architecture, these functions should require a validated session token or cryptographic credential before processing requests.\nExploitation occurs when an unauthenticated remote attacker sends specially crafted requests to the vulnerable endpoints associated with the appliance or application. Because the target component fails to validate the identity of the requester, the system treats the incoming request as legitimate and proceeds to execute the associated function.\nThe attack flow follows a direct exploitation pattern: First, the attacker identifies the reachable network interface hosting the management or control plane of the Dell SCG 5.0 instance. Second, the attacker sends an unauthorized payload or command to the target function, bypassing the expected handshake process. Since the underlying service does not perform an authorization handshake, the function triggers immediately upon receipt of the request.\nThe scope of impact is critical, as the unauthorized access provided by this vulnerability can facilitate full control over the appliance's management functions. Depending on the specific function exposed, an attacker could extract sensitive diagnostic data, modify gateway configuration parameters, or leverage the appliance as a pivot point within the internal network. The attack does not require any existing privileges, making it accessible to any external entity capable of establishing a network connection to the service port.\nThe vulnerability persists across all Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and all Dell SCG 5.0 Application versions prior to 5.36.00.00. The lack of authentication serves as a fundamental architectural oversight in the request handling lifecycle of the affected components, failing to verify the caller's authority before committing to high-privilege operations."
}