Sceawere

Vulnerability Detail

CVE-2026-80166UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
3h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-269: Improper Privilege Management
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-09-07T17:17:25.570Z",
  "pubdate": "2026-09-07T17:17:25.570Z",
  "executiveSummary": "This vulnerability involves an Improper Privilege Management flaw identified in Dell SCG 5.0 Appliance and Application versions. The vulnerability resides within the appliance's access control mechanisms, allowing for potential unauthorized elevation of privileges. Successful exploitation requires an unauthenticated attacker to possess local access to the target system. The primary risk implication involves an attacker transitioning from a restricted, low-privilege environment to a higher-privilege state, which could lead to full administrative compromise of the appliance. Given the requirement for local access, this vulnerability represents a significant security concern for environments where physical or logical access to the appliance host cannot be strictly audited or constrained. Mitigation requires updating affected components to the specified secure versions.",
  "technicalDetails": "The vulnerability originates from a failure in the Dell SCG 5.0 Appliance (prior to 5.36.00.16) and Application (prior to 5.36.00.00) to adequately enforce privilege boundaries. Improper Privilege Management occurs when a system fails to verify or restrict the functional capabilities of a user or process effectively, allowing for unauthorized vertical privilege escalation.\nThe root cause is identified as an flaw in the internal access control logic of the appliance, which does not properly sanitize or validate the security context of local actors. In a standard operation, the appliance components are expected to operate within defined security realms. However, the flaw allows an entity operating without prior authentication—such as an attacker with shell access or other local interface access—to interact with internal processes or system management functions that should typically be restricted to administrative roles.\nThe exploitation flow initiates with the attacker establishing a local session on the appliance host. Because the system exhibits insufficient privilege enforcement, the attacker can leverage specific, undocumented, or unprotected pathways within the application architecture to invoke elevated operations. This might involve the execution of system-level commands, modification of configuration files, or the direct manipulation of administrative binaries that are improperly guarded against low-privileged interaction. By bypassing the intended access control checks, the attacker successfully transitions from an unprivileged, local, unauthenticated state to an escalated privilege context.\nThe post-exploitation impact is severe, as privilege escalation typically facilitates the total compromise of the appliance's security integrity. Once elevated, the attacker can install persistent backdoors, exfiltrate sensitive data managed by the Dell SCG, modify security logs to obscure malicious activity, or leverage the appliance as a pivot point for lateral movement within the management network. The vulnerability effectively nullifies the authentication perimeter for local users, exposing all administrative functions to exploitation by anyone capable of establishing a local presence on the underlying infrastructure."
}
CVE-2026-80166: Dell SCG Privilege Escalation Vulnerability (HIGH Severity, CVSS: 7.8) - Sceawere