Sceawere

Vulnerability Detail

CVE-2026-80178UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
1h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-269: Improper Privilege Management
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-07T13:20:39.170Z",
  "pubdate": "2026-09-07T13:20:39.170Z",
  "executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 is susceptible to an Improper Privilege Management vulnerability that allows for unauthorized elevation of privileges.\nThe vulnerability affects both the Dell SCG 5.0 Appliance (prior to 5.36.00.16) and the Dell SCG 5.0 Application (prior to 5.36.00.00).\nAn attacker possessing low-privileged local access can leverage this flaw to gain elevated permissions within the system environment.\nThis represents a significant security risk, as successful exploitation enables an attacker to bypass standard access controls, potentially leading to full administrative compromise of the underlying gateway service.\nThe vulnerability is restricted to local exploitation vectors, meaning an adversary must first establish an authenticated local presence on the host system to initiate the attack.",
  "technicalDetails": "The vulnerability is categorized as an Improper Privilege Management issue, arising from insufficient validation or enforcement of permission boundaries within the Dell SCG 5.0 infrastructure.\nThe root cause pertains to how the application or appliance manages security tokens or process execution contexts when invoked by low-privileged user accounts.\nBecause the system fails to correctly constrain the capabilities of low-privileged users, a local attacker can manipulate or trigger processes that operate with higher authority than the attacker's original security context.\nThe attack flow begins with the adversary establishing local access to the SCG environment. By interacting with specific, improperly secured interfaces or services provided by the SCG application, the attacker executes a sequence of commands designed to trigger a privilege-sensitive operation.\nSince the affected components perform these operations without proper privilege verification, the system executes the malicious or unauthorized instruction using the credentials of a higher-privileged user or the system service account itself.\nAffected versions include Dell SCG 5.0 Appliance builds earlier than 5.36.00.16 and Dell SCG 5.0 Application builds earlier than 5.36.00.00.\nThe exploit does not require remote network access, relying entirely on the local exploitation of internal service logic that fails to adhere to the Principle of Least Privilege.\nPost-exploitation impact is severe, as the successful elevation allows an attacker to perform administrative actions, access sensitive configuration data, modify system settings, or pivot to other internal resources accessible through the gateway.\nThe lack of strict process isolation or robust permission checks within the application's core logic enables this escalation, effectively bypassing the intended security architecture of the gateway."
}
CVE-2026-80178: Dell SCG Privilege Escalation Vulnerability (MEDIUM Severity, CVSS: 5.5) - Sceawere