CVE-2026-80131
7.4Dell · Secure Connect Gateway 5.0
Dell Secure Connect Gateway 5.0 contains a path traversal vulnerability that allows an unauthenticated remote attacker to potentially achieve remote execution on the target system.
Executive summary
A critical path traversal vulnerability in Dell Secure Connect Gateway 5.0 allows unauthenticated remote attackers to execute arbitrary code, posing a severe risk to system integrity.
Vulnerability
This flaw is identified as a path traversal vulnerability (CWE-22) that permits an unauthenticated attacker to bypass directory restrictions. By manipulating file paths, an attacker can access or execute unauthorized files, leading to remote code execution.
Business impact
The ability for an unauthenticated attacker to achieve remote execution represents a critical threat to the confidentiality and integrity of the affected environment. With a CVSS score of 7.4, this vulnerability enables unauthorized control over the gateway, which could lead to total system compromise, exfiltration of sensitive configuration data, or lateral movement within the network. Immediate remediation is required to prevent potential exploitation of this high-severity access point.
Remediation
Immediate Action: Update Dell Secure Connect Gateway to version 5.36.00.16 (Appliance) or 5.36.00.00 (Application) or later as specified in the official Dell security advisory.
Proactive Monitoring: Review system and application access logs for suspicious path traversal patterns, such as sequences involving dot-dot-slash characters in URI requests.
Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to detect and block directory traversal attempts targeting the Secure Connect Gateway interface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for remote code execution, organizations must prioritize patching these Dell Secure Connect Gateway instances. Administrators should verify the current version of their deployment against the provided thresholds and apply the necessary updates immediately to eliminate this significant security gap.
More Dell CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section