Sceawere
Vulnerability Detail
CVE-2026-80178UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell SCG Privilege Escalation Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 1h ago
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- Attack Type
- CWE-269: Improper Privilege Management
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-07T13:20:39.170Z",
"pubdate": "2026-09-07T13:20:39.170Z",
"executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 is susceptible to an Improper Privilege Management vulnerability that allows for unauthorized elevation of privileges.\nThe vulnerability affects both the Dell SCG 5.0 Appliance (prior to 5.36.00.16) and the Dell SCG 5.0 Application (prior to 5.36.00.00).\nAn attacker possessing low-privileged local access can leverage this flaw to gain elevated permissions within the system environment.\nThis represents a significant security risk, as successful exploitation enables an attacker to bypass standard access controls, potentially leading to full administrative compromise of the underlying gateway service.\nThe vulnerability is restricted to local exploitation vectors, meaning an adversary must first establish an authenticated local presence on the host system to initiate the attack.",
"technicalDetails": "The vulnerability is categorized as an Improper Privilege Management issue, arising from insufficient validation or enforcement of permission boundaries within the Dell SCG 5.0 infrastructure.\nThe root cause pertains to how the application or appliance manages security tokens or process execution contexts when invoked by low-privileged user accounts.\nBecause the system fails to correctly constrain the capabilities of low-privileged users, a local attacker can manipulate or trigger processes that operate with higher authority than the attacker's original security context.\nThe attack flow begins with the adversary establishing local access to the SCG environment. By interacting with specific, improperly secured interfaces or services provided by the SCG application, the attacker executes a sequence of commands designed to trigger a privilege-sensitive operation.\nSince the affected components perform these operations without proper privilege verification, the system executes the malicious or unauthorized instruction using the credentials of a higher-privileged user or the system service account itself.\nAffected versions include Dell SCG 5.0 Appliance builds earlier than 5.36.00.16 and Dell SCG 5.0 Application builds earlier than 5.36.00.00.\nThe exploit does not require remote network access, relying entirely on the local exploitation of internal service logic that fails to adhere to the Principle of Least Privilege.\nPost-exploitation impact is severe, as the successful elevation allows an attacker to perform administrative actions, access sensitive configuration data, modify system settings, or pivot to other internal resources accessible through the gateway.\nThe lack of strict process isolation or robust permission checks within the application's core logic enables this escalation, effectively bypassing the intended security architecture of the gateway."
}