CVE-2026-80132

8.1

Dell · Secure Connect Gateway

Dell Secure Connect Gateway contains a missing authentication vulnerability allowing unauthenticated remote attackers to potentially gain unauthorized access to critical functions.

Executive summary

A missing authentication vulnerability in Dell Secure Connect Gateway allows unauthenticated remote attackers to gain unauthorized access, posing a significant risk to system integrity.

Vulnerability

The software suffers from a missing authentication for critical function vulnerability (CWE-306), which permits an unauthenticated attacker with remote network access to interact with sensitive administrative or functional endpoints.

Business impact

This vulnerability carries a CVSS score of 8.1, indicating a high severity risk that could lead to full system compromise. Unauthorized access to the Secure Connect Gateway may allow attackers to intercept sensitive data, modify system configurations, or use the appliance as a pivot point for further lateral movement within the environment.

Remediation

Immediate Action: Upgrade the Dell Secure Connect Gateway Appliance to version 5.36.00.16 or higher, and the Application to version 5.36.00.00 or higher, as directed by the vendor security advisory.

Proactive Monitoring: Review system access logs for anomalous remote connection attempts or unauthorized authentication requests directed at administrative endpoints.

Compensating Controls: Implement strict network segmentation and restrict access to the Secure Connect Gateway interface to trusted management IP addresses via a firewall or VPN to minimize the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the high CVSS score and the potential for unauthenticated remote access, this vulnerability must be addressed as a priority. Administrators should verify their current version of the Dell Secure Connect Gateway immediately and apply the necessary patches to prevent exploitation of this authentication flaw.

More Dell CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources