CVE-2026-61409

7.3

Dell · Secure Connect Gateway (SCG)

Dell Secure Connect Gateway contains an OS command injection vulnerability, allowing unauthenticated remote attackers to execute arbitrary system commands.

Executive summary

A critical OS command injection vulnerability in Dell Secure Connect Gateway allows unauthenticated remote attackers to achieve remote code execution on affected systems.

Vulnerability

This vulnerability is an improper neutralization of special elements used in an OS command (CWE-78). It allows an unauthenticated remote attacker to inject and execute arbitrary commands with the privileges of the application service.

Business impact

The vulnerability carries a CVSS score of 7.3, reflecting its high potential for system compromise. Successful exploitation grants an attacker the ability to execute arbitrary code, which can lead to complete unauthorized access, data exfiltration, or the deployment of persistent threats within the network. Because the flaw is exploitable by unauthenticated remote users, the attack surface is significant for any organization with exposed instances of this gateway.

Remediation

Immediate Action: Update the Dell Secure Connect Gateway Application to version 5.36.00.00 or later, and the Appliance version to 5.36.00.16 or later, as specified in the vendor security advisory.

Proactive Monitoring: Review system and application logs for unusual process execution patterns or unexpected shell commands originating from the web service account.

Compensating Controls: Deploy Web Application Firewall (WAF) rules to inspect and filter incoming traffic for common OS command injection characters such as semicolons, pipes, or backticks.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This high-severity vulnerability poses a substantial risk to organizational infrastructure due to the lack of required authentication for exploitation. Security teams should prioritize patching affected Dell Secure Connect Gateway instances immediately. If patching cannot be performed during the current maintenance window, restrict network access to the management interface to trusted internal IP addresses only.

More Dell CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources