Sceawere

Vulnerability Detail

CVE-2026-80128UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG Improper Authentication Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
1h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-287: Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-09-07T14:16:54.580Z",
  "pubdate": "2026-09-07T14:16:54.580Z",
  "executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 is affected by an Improper Authentication vulnerability, categorized under CWE-287. This security defect allows a low-privileged, remotely authenticated attacker to bypass critical protection mechanisms embedded within the appliance or application layers.\nThe vulnerability originates from a flaw in how the system validates or enforces authentication protocols, enabling unauthorized entities to circumvent security controls that should otherwise restrict their actions. Successful exploitation could lead to unauthorized access to sensitive functionalities, unauthorized configuration changes, or potential exposure of internal system resources.\nThe flaw impacts Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. Given that the attack requires only low-privileged remote access, the risk implication is significant as it lowers the barrier for internal lateral movement or administrative control escalation. Organizations are advised to prioritize updating to the specified patched versions to remediate the authentication logic errors.",
  "technicalDetails": "The vulnerability is identified as an Improper Authentication issue, where the Dell SCG platform fails to adequately verify the authenticity of a user or process requesting access to privileged resources. By failing to properly enforce authentication checks at specific entry points, the system allows an authenticated user with low-level privileges to interact with functions intended for higher-privileged roles or restricted service segments.\nThe attack flow initiates when a remote attacker, already possessing a low-privileged account on the target system, identifies an exposed API endpoint or management interface that improperly validates the caller's authorization token or session identity. Instead of enforcing standard Role-Based Access Control (RBAC) checks, the affected application logic allows the user to bypass the expected validation flow. This effectively circumvents the authentication barrier, granting the attacker the ability to execute unauthorized administrative actions or access system-level configurations without possessing the requisite permissions.\nThe root cause resides in the authentication middleware or the backend authorization logic responsible for verifying user privilege levels against requested operations. In the context of Dell SCG 5.0, this suggests that the session state or request metadata is not being consistently validated against the requested function's required privilege level. Consequently, the application assumes that the caller has been vetted for the requested operation, despite the user's lack of appropriate credentials.\nThe impact of this bypass is significant, as it enables an attacker to manipulate the security posture of the appliance. Post-exploitation, an attacker may perform unauthorized operations such as modification of system settings, disabling security logging, or potentially extracting sensitive diagnostic data that the platform collects as part of its function. Because the vulnerability exists within the management or application layer, the network exposure is restricted to users who have established a remote session, but the escalation potential significantly undermines the principle of least privilege within the SCG deployment.\nAffected versions include Dell SCG 5.0 Appliance builds earlier than 5.36.00.16 and Dell SCG 5.0 Application builds earlier than 5.36.00.00. Remediation requires upgrading the underlying firmware or software application stack to the versions where the authentication logic has been hardened to ensure that all requests are subjected to mandatory authorization checks before execution."
}
CVE-2026-80128: Dell SCG Improper Authentication Bypass (MEDIUM Severity, CVSS: 6.4) - Sceawere