Sceawere

Vulnerability Detail

CVE-2026-79946UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
23h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-87: Improper Neutralization of Alternate XSS Syntax
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-09T16:17:08.640Z",
  "pubdate": "2026-09-09T16:17:08.640Z",
  "executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 is susceptible to a vulnerability categorized as Improper Neutralization of Alternate XSS Syntax, which facilitates stored or reflected Cross-Site Scripting (XSS).\nThis security flaw allows an unauthenticated, remote attacker to inject malicious scripts into the web-based management interface of the appliance.\nSuccessful exploitation compromises the integrity of the user's browser session within the context of the application, potentially leading to unauthorized actions performed on behalf of legitimate users, credential theft, or redirection to malicious domains.\nThe vulnerability affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00.\nDue to the remote and unauthenticated nature of the attack vector, the risk is significant, requiring immediate attention through administrative patching to ensure the confidentiality and integrity of the management environment.",
  "technicalDetails": "The vulnerability stems from the application's failure to properly sanitize or neutralize input strings that utilize alternate XSS syntax, allowing the execution of arbitrary JavaScript in the victim's browser context.\nThe primary root cause is identified as improper neutralization of user-supplied data, which permits the bypassing of conventional filter mechanisms. By leveraging non-standard XSS syntax, an attacker can bypass blacklists that may only be looking for traditional <script> tags, thereby successfully injecting malicious payloads that the web application renders as trusted content.\nThe exploitation flow begins with an unauthenticated attacker identifying an entry point within the Dell SCG web interface where user-controllable input is reflected back to the client side without adequate encoding. The attacker crafts a payload utilizing alternate encoding or obfuscation techniques designed to evade existing input validation logic. When an unsuspecting user, such as an administrator, accesses the compromised page or view, the malicious payload is interpreted by the browser and executed within the security domain of the SCG appliance.\nBecause the vulnerability is exploitable remotely by an unauthenticated attacker, it presents a substantial risk to the administrative control plane of the appliance. The post-exploitation impact allows for the unauthorized execution of scripts that can perform actions including session hijacking, exfiltration of sensitive session tokens, unauthorized configuration changes, or the alteration of displayed content for phishing purposes. This vulnerability specifically impacts Dell SCG 5.0 Appliance and Application editions, necessitating an update to the corrected version benchmarks (5.36.00.16 for Appliance and 5.36.00.00 for Application) to resolve the underlying input handling deficiency."
}
CVE-2026-79946: Dell SCG XSS Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere