Sceawere

Vulnerability Detail

CVE-2026-80054UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG Improper Permission Assignment

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
2h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-732: Incorrect Permission Assignment for Critical Resource
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-07T16:17:29.690Z",
  "pubdate": "2026-09-07T16:17:29.690Z",
  "executiveSummary": "This vulnerability involves an Incorrect Permission Assignment for Critical Resource within Dell SCG 5.0 Appliance and Application versions. The flaw resides in the handling of access control mechanisms for sensitive system resources, allowing local users to bypass intended security constraints.\nAffected products include Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. The risk is categorized as significant because it allows a low-privileged local attacker to gain unauthorized access to critical system assets.\nExploitation requires the attacker to already possess local access to the target environment. By manipulating file or resource permissions that were improperly configured during the deployment or update process, an attacker can escalate privileges or access data they are not authorized to view or modify. This undermines the principle of least privilege, potentially compromising the integrity and confidentiality of the entire appliance environment. Successful exploitation provides a foothold for further malicious activity, such as data exfiltration or system persistence. Organizations are advised to update to the remediated versions to restore proper access control enforcement.",
  "technicalDetails": "The vulnerability is rooted in an Improper Permission Assignment for Critical Resource, which occurs when the security model governing access to files, directories, or system processes is inadequately defined or restricted. In the context of Dell SCG 5.0, the appliance or application environment fails to enforce strict ownership or permission bits on sensitive files that define system state or configuration.\nThe root cause suggests that the deployment scripts or internal security configuration mechanisms assign overly permissive access rights—such as global read or write permissions—to objects that should be restricted to administrative accounts. Because the appliance environment executes with elevated system-level privileges, a local user who is normally restricted to a low-privileged shell or service account can leverage these broad permissions to interact with or modify these critical resources.\nThe exploitation flow begins with the attacker gaining local access via the command line or an existing low-privileged service interface. Once inside the environment, the attacker identifies the misconfigured resource—typically a configuration file, a binary, or a protected data store that lacks proper 'chmod' or 'chown' enforcement. The attacker proceeds to modify, replace, or extract data from the targeted resource. For example, if a configuration file containing credentials or environment variables is world-readable, the attacker can harvest sensitive information. If a system-critical binary or script is world-writable, the attacker can inject malicious code, which will subsequently execute with the context of the higher-privileged service or the root user, leading to full system compromise.\nThis vulnerability is confined to local access, meaning it is not directly reachable over the network unless the attacker has already compromised a user account on the host. However, in multi-tenant or multi-user environments where low-privileged users exist, this flaw represents a significant risk for privilege escalation. The scope of impact is limited to the local operating environment of the Dell SCG instance. The vulnerability persists until the system permissions are corrected via the provided software updates, which likely re-apply the correct access control lists (ACLs) and permission structures to all relevant system resources, ensuring that the principle of least privilege is upheld."
}
CVE-2026-80054: Dell SCG Improper Permission Assignment (MEDIUM Severity, CVSS: 5.5) - Sceawere