Sceawere
Vulnerability Detail
CVE-2026-79964UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Improper Neutralization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 20h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- Attack Type
- CWE-116: Improper Encoding or Escaping of Output
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Escape, Meta, or Control Sequences vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to launch of phishing attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-09T14:17:18.413Z",
"pubdate": "2026-09-09T14:17:18.413Z",
"executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) are susceptible to an Improper Neutralization of Escape, Meta, or Control Sequences vulnerability. This security flaw allows an unauthenticated, remote attacker to inject malicious control sequences into the system, potentially facilitating large-scale phishing campaigns. The vulnerability represents a significant risk to organizational integrity, as it provides a vector for social engineering attacks originating from a trusted infrastructure component. Exploitation does not require authentication, granting external adversaries the ability to manipulate system-generated outputs or notifications. This creates a critical trust-abuse scenario where the appliance could be coerced into distributing malicious links or deceptive content to legitimate users or administrators. Immediate patching is required to neutralize this risk and prevent the weaponization of the SCG platform as a delivery mechanism for malicious artifacts.",
"technicalDetails": "The vulnerability is rooted in the failure of the Dell SCG application to properly sanitize and validate input before processing or rendering data that may contain escape, meta, or control sequences. Improper neutralization occurs when the application accepts user-influenced input and fails to neutralize characters that the underlying system, browser, or terminal interpreter recognizes as commands or control codes. By injecting specific character sequences, an attacker can manipulate the formatting, content, or control flow of data handled by the SCG software.\nFrom an attack flow perspective, an unauthenticated remote actor identifies an entry point within the SCG interface or API that facilitates the inclusion of unsanitized input. The attacker crafts a payload consisting of escape sequences or control characters designed to alter the perceived context of the application's output. Once the payload is submitted, the application fails to treat the input as literal data, instead executing the injected sequences as instructions. In the context of the reported phishing impact, this allows the attacker to inject malicious URLs, fraudulent messaging, or spoofed UI elements into legitimate notifications or reports generated by the SCG appliance.\nThis vulnerability is particularly severe due to the remote, unauthenticated nature of the exploit. No prior knowledge of internal credentials or administrative privileges is necessary to initiate the attack sequence. The network exposure is limited only by the reachability of the SCG instance's listener ports. Because the SCG appliance operates as a trusted gateway within the enterprise environment, any content modified through this injection technique carries an implicit level of trust from end-users, significantly increasing the success rate of phishing attempts.\nPost-exploitation, the impact involves the dissemination of deceptive material originating from a secure, authenticated-looking source. This can result in credential harvesting, the distribution of malware-laden payloads, or unauthorized redirection of users to malicious infrastructure. The failure to maintain secure boundaries between untrusted user input and application-rendered output renders the system a potential platform for persistent social engineering attacks. Remediation requires updating the SCG Appliance to version 5.36.00.16 or higher, or the SCG Application to version 5.36.00.00 or higher, to implement robust input validation and character neutralization routines."
}