Sceawere
Vulnerability Detail
CVE-2026-80132UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Missing Authentication Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 1h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- Attack Type
- CWE-306: Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-09-07T13:20:38.670Z",
"pubdate": "2026-09-07T13:20:38.670Z",
"executiveSummary": "This vulnerability involves a Missing Authentication for Critical Function defect within Dell Secure Connect Gateway (SCG).\nThe flaw allows unauthenticated, remote attackers to access sensitive functionality without prior validation of credentials.\nAffected systems include Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00.\nSuccessful exploitation grants unauthorized access to restricted interfaces or internal logic, potentially leading to full compromise of the appliance management features.\nThis represents a high-severity security risk as it bypasses primary security controls, allowing unauthorized entities to perform administrative or operational actions remotely.\nThe vulnerability does not require prior knowledge of user accounts or existing authentication bypass techniques, significantly lowering the barrier for entry for an attacker.",
"technicalDetails": "The vulnerability is identified as a 'Missing Authentication for Critical Function' (CWE-306). It resides within the API or web management layer of the Dell Secure Connect Gateway (SCG) infrastructure.\nThe root cause of this vulnerability is the failure of the application to enforce authentication checks on specific, sensitive endpoints. During the request handling lifecycle, the application processes requests directed at administrative or functional paths without verifying if the requesting entity possesses a valid session token, identity context, or required authorization header.\nAn unauthenticated attacker can exploit this by sending specially crafted HTTP requests to the target appliance. Since the appliance performs no validation, it treats the request as legitimate and executes the requested logic. This behavior typically suggests that the vulnerable component operates under the assumption that it is unreachable by external, unauthorized parties, or that security controls were improperly scoped to internal-only methods.\nThe attack flow proceeds as follows: First, the attacker identifies the exposed management interface of the SCG appliance. Second, the attacker interacts with the target function—potentially an endpoint responsible for configuration, telemetry management, or internal routing—via a direct network request. Third, the application processes the request, bypassing the security middleware that typically enforces authentication. Finally, the application executes the underlying logic associated with the critical function.\nPost-exploitation impact includes unauthorized modification of appliance settings, potential exposure of diagnostic data, or the redirection of management traffic. Because the vulnerability allows unauthenticated access to critical functions, the attacker essentially gains an administrative foothold without needing to compromise local credentials or exploit secondary vulnerabilities. This bypasses the Principle of Least Privilege and undermines the integrity of the appliance’s operational security model.\nThe affected product ecosystem covers both the SCG 5.0 Appliance (pre-5.36.00.16) and the SCG 5.0 Application (pre-5.36.00.00). The vulnerability is accessible over the network, making any instance exposed to untrusted networks (such as the internet or an insecure management VLAN) susceptible to exploitation."
}