Sceawere

Vulnerability Detail

CVE-2026-80131UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Path Traversal Remote Execution

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
1h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-09-07T14:16:54.933Z",
  "pubdate": "2026-09-07T14:16:54.933Z",
  "executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application versions are susceptible to a critical Path Traversal vulnerability (CWE-22).\nThis vulnerability allows an unauthenticated, remote attacker to manipulate file paths, potentially resulting in unauthorized Remote Code Execution (RCE) on the target system.\nThe vulnerability affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00.\nSuccessful exploitation poses a severe risk to the confidentiality, integrity, and availability of the affected system, as it grants attackers the ability to execute arbitrary commands without requiring prior authentication or administrative privileges.\nThe vulnerability highlights a failure in input validation mechanisms within the application's file handling processes, enabling attackers to escape the intended directory constraints.",
  "technicalDetails": "The vulnerability stems from improper input validation and sanitization of user-supplied data used in file system operations. Specifically, the application fails to adequately constrain file path references, allowing an attacker to traverse the directory structure using techniques such as dot-dot-slash (../) sequences.\nThis Path Traversal flaw originates in the handling of file requests where input parameters are passed directly to system file APIs without sufficient neutralization of directory traversal characters. By injecting malicious path sequences into input fields that govern file access, an attacker can move outside the root directory of the application.\nThe exploitation flow typically begins with an unauthenticated remote attacker identifying a web endpoint or API function that accepts a file path or resource identifier as an argument. The attacker crafts a request containing directory traversal payloads to navigate to sensitive system files or executable binaries outside the protected application directory.\nBy manipulating these paths, the attacker can target configuration files, system binaries, or application-specific scripts. If the application environment allows for the execution of files residing in the path manipulated by the attacker, this traversal can be escalated to full Remote Code Execution. The lack of authentication requirements significantly lowers the barrier for exploitation, allowing any remote actor with network reach to the SCG management interface to initiate the attack sequence.\nOnce the attacker successfully traverses to a directory with write or execution permissions, they may be able to upload or overwrite existing system files. The payload behavior typically involves gaining access to the underlying operating system environment of the SCG appliance. Post-exploitation, the attacker achieves persistence or full administrative control, enabling them to execute arbitrary system commands, exfiltrate sensitive data, or further compromise the network segment where the SCG resides."
}
CVE-2026-80131: Path Traversal Remote Execution (HIGH Severity, CVSS: 7.4) - Sceawere