Sceawere

Vulnerability Detail

CVE-2026-79971UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG Script Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
20h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-1236: Improper Neutralization of Formula Elements in a CSV File
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Sanitization of Custom Special Characters vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-09T14:17:18.650Z",
  "pubdate": "2026-09-09T14:17:18.650Z",
  "executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 is susceptible to an improper sanitization of custom special characters vulnerability, which facilitates script injection attacks. This vulnerability allows an unauthenticated, remote attacker to execute malicious scripts within the context of the user's browser or the application's interface. The flaw affects both the SCG 5.0 Appliance (versions prior to 5.36.00.16) and the SCG 5.0 Application (versions prior to 5.36.00.00). Exploitation of this vulnerability poses a significant risk to the integrity and confidentiality of the appliance, as it may lead to unauthorized actions, session hijacking, or the execution of arbitrary code within the target environment. The primary security implication is the potential for cross-site scripting (XSS) or similar injection-based attacks that bypass standard security controls. By leveraging this lack of sanitization, an attacker can manipulate application responses to deliver malicious payloads to unsuspecting users or administrators, thereby compromising the administrative session and potentially leading to further unauthorized access or lateral movement within the network.",
  "technicalDetails": "The vulnerability resides in the input handling mechanisms of Dell SCG 5.0, where the system fails to sufficiently sanitize user-supplied input containing custom special characters. The root cause is categorized as an Improper Sanitization of Custom Special Characters, which indicates a failure in the application's validation logic to neutralize malicious payloads before they are processed or rendered by the web interface. In a typical attack flow, the attacker identifies entry points within the Dell SCG interface that accept user input and subsequently reflect that input back to the user or store it within the application's state.\nBecause the input is not appropriately filtered or encoded, an attacker can inject crafted scripts—such as JavaScript—into these fields. When a legitimate user or administrator interacts with the compromised component, the application renders the malicious script. Because the application does not implement robust content security policies or context-aware output encoding, the browser interprets the injected code as legitimate instructions, executing it within the security domain of the SCG session. This bypasses the need for existing authentication, as the attack is delivered via a remote vector against an unauthenticated interface.\nThe exploitation vector is external and remote, requiring only network access to the target Dell SCG instance. Upon successful injection, the payload executes within the target's web browser, facilitating actions such as credential theft via session token exfiltration, unauthorized reconfiguration of appliance settings, or performing actions on behalf of the authenticated user. This vulnerability affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. The post-exploitation impact includes potential administrative session takeover, which could lead to full control over the gateway functionality and subsequent compromise of managed devices connected through the gateway. Effective remediation requires ensuring that all user-controllable input is subjected to strict allow-list validation and appropriate context-aware output encoding to prevent the execution of injected script content."
}
CVE-2026-79971: Dell SCG Script Injection Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere