CVE-2026-80132
8.1Dell · Secure Connect Gateway
Dell Secure Connect Gateway contains a missing authentication vulnerability allowing unauthenticated remote attackers to potentially gain unauthorized access to critical functions.
Executive summary
A missing authentication vulnerability in Dell Secure Connect Gateway allows unauthenticated remote attackers to gain unauthorized access, posing a significant risk to system integrity.
Vulnerability
The software suffers from a missing authentication for critical function vulnerability (CWE-306), which permits an unauthenticated attacker with remote network access to interact with sensitive administrative or functional endpoints.
Business impact
This vulnerability carries a CVSS score of 8.1, indicating a high severity risk that could lead to full system compromise. Unauthorized access to the Secure Connect Gateway may allow attackers to intercept sensitive data, modify system configurations, or use the appliance as a pivot point for further lateral movement within the environment.
Remediation
Immediate Action: Upgrade the Dell Secure Connect Gateway Appliance to version 5.36.00.16 or higher, and the Application to version 5.36.00.00 or higher, as directed by the vendor security advisory.
Proactive Monitoring: Review system access logs for anomalous remote connection attempts or unauthorized authentication requests directed at administrative endpoints.
Compensating Controls: Implement strict network segmentation and restrict access to the Secure Connect Gateway interface to trusted management IP addresses via a firewall or VPN to minimize the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Given the high CVSS score and the potential for unauthenticated remote access, this vulnerability must be addressed as a priority. Administrators should verify their current version of the Dell Secure Connect Gateway immediately and apply the necessary patches to prevent exploitation of this authentication flaw.
More Dell CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section