Sceawere

Vulnerability Detail

CVE-2026-80238UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell SCG Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
1h ago
Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
Attack Type
CWE-250: Execution with Unnecessary Privileges
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is considered critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a password by leveraging the exposed Docker socket. Additionally, an attacker who compromises a service running within the orchestrator container can access the same socket and escape the container boundary to obtain host-level control. Dell recommends that customers upgrade at the earliest opportunity.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-09-07T13:20:39.293Z",
  "pubdate": "2026-09-07T13:20:39.293Z",
  "executiveSummary": "Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application versions are susceptible to an Execution with Unnecessary Privileges vulnerability.\nThe vulnerability originates from improper handling of the Docker socket, allowing for a bypass of protection mechanisms.\nThe impact is critical, as it facilitates unauthorized privilege escalation to root-level access on the host operating system.\nAffected products include Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00.\nExploitation requires local access, where an attacker—such as a low-privileged operator with SSH access or a compromised service within the orchestrator container—can leverage the exposed Docker socket.\nThe risk implication is total host compromise, enabling the attacker to execute arbitrary commands with administrative privileges, bypassing established security boundaries.\nImmediate upgrade to the specified patched versions is required to remediate this security risk.",
  "technicalDetails": "The vulnerability is classified as an Execution with Unnecessary Privileges, stemming from insecure configuration and exposure of the Docker daemon socket within the Dell SCG environment.\nThe Docker socket (/var/run/docker.sock) is a powerful interface that provides full control over the Docker daemon. When exposed to unprivileged users or containers, it effectively grants the possessor the same permissions as the root user on the host system.\nIn the context of the Dell SCG 5.0 Appliance and Application, the orchestrator container environment incorrectly manages access to this socket. This configuration failure allows local entities—specifically low-privileged SSH users or compromised services running within the orchestrator container—to interact directly with the Docker daemon.\nThe attack flow for a low-privileged SSH user involves utilizing the existing SSH session to invoke the Docker CLI or direct API requests to the exposed socket. By crafting requests to the Docker daemon, the attacker can instantiate new containers with host directory mounts or execute commands directly within the context of existing containers that run with elevated privileges.\nFor an attacker compromising a service within the orchestrator container, the exploitation involves utilizing the container-local access to the same exposed Docker socket. Once access is obtained, the attacker can perform a container escape. By manipulating the daemon, the attacker can start a privileged container that mounts the host's root filesystem, allowing the attacker to modify sensitive system files, install backdoors, or extract credentials, effectively obtaining persistent host-level control.\nThe root cause is the lack of strict access control and container hardening around the Docker runtime environment. By failing to restrict the scope and permission set of the Docker socket, the system creates a path for privilege escalation that bypasses standard Linux user permissions and container isolation boundaries.\nAffected versions include Dell SCG 5.0 Appliance prior to 5.36.00.16 and Dell SCG 5.0 Application prior to 5.36.00.00. The post-exploitation impact is complete host compromise, where the attacker inherits the security context of the root user, negating the appliance's security model."
}
CVE-2026-80238: Dell SCG Privilege Escalation Vulnerability (CRITICAL Severity, CVSS: 9.3) - Sceawere