CVE-2026-79643

7.3

Dell · Secure Connect Gateway

Dell Secure Connect Gateway 5.0 contains an incorrect operator vulnerability that allows unauthenticated remote attackers to gain unauthorized access to the system.

Executive summary

A critical vulnerability in Dell Secure Connect Gateway allows unauthenticated remote attackers to bypass security controls and gain unauthorized access to the appliance.

Vulnerability

This flaw involves the use of an incorrect operator, which undermines logical checks within the application. An unauthenticated remote attacker can exploit this condition to bypass intended access restrictions.

Business impact

The ability for an unauthenticated attacker to gain unauthorized access poses a severe risk to the confidentiality and integrity of the managed environment. With a CVSS score of 7.3, this high severity vulnerability could lead to the exposure of sensitive gateway data or the compromise of connected infrastructure. Organizations relying on this gateway for secure connectivity must prioritize remediation to prevent potential lateral movement by unauthorized parties.

Remediation

Immediate Action: Update the Dell Secure Connect Gateway Application to version 5.36.00.00 or later, or the Appliance to version 5.36.00.16 or later, as specified in the vendor security advisory.

Proactive Monitoring: Review system and application access logs for any suspicious or unauthorized authentication attempts originating from untrusted network segments.

Compensating Controls: Implement strict network access control lists to restrict access to the management interface of the Secure Connect Gateway to authorized administrative IP addresses only.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for unauthenticated remote access, this vulnerability should be treated as a priority for all administrators. You must verify your current firmware or software version against the fixed releases provided by Dell and apply the necessary patches immediately to eliminate the exposure window.

More Dell CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources