CVE-2026-79645
8.2Dell · Secure Connect Gateway
Dell Secure Connect Gateway contains a missing authentication vulnerability that allows unauthenticated remote attackers to gain unauthorized access to critical functions.
Executive summary
A critical authentication bypass vulnerability in Dell Secure Connect Gateway allows unauthenticated remote attackers to gain unauthorized access to the system.
Vulnerability
This vulnerability involves a failure to perform adequate authentication checks for critical functions. An unauthenticated attacker can exploit this remotely to interact with sensitive system components without valid credentials.
Business impact
The ability for an unauthenticated user to interact with critical administrative functions poses a severe risk to organizational infrastructure. With a CVSS score of 8.2, this flaw could lead to unauthorized system modification or data exposure, potentially resulting in significant operational downtime or the compromise of connected managed assets.
Remediation
Immediate Action: Upgrade the Dell Secure Connect Gateway Appliance to version 5.36.00.16 or later, or the Application component to 5.36.00.00 or later, as specified in the vendor security advisory.
Proactive Monitoring: Monitor system access logs for anomalous login attempts or unauthorized requests to administrative endpoints, particularly those originating from external or untrusted network segments.
Compensating Controls: Deploy Web Application Firewall rules to restrict access to the Secure Connect Gateway interface, ensuring that only known, authorized IP addresses can reach the management service.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high severity of this vulnerability and the potential for unauthorized administrative control, organizations should prioritize patching as an immediate operational requirement. Verify that all instances of the Secure Connect Gateway are updated to the specified versions to eliminate the risk of remote, unauthenticated access.
More Dell CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section