CVE-2026-80133

7.4

Dell · Secure Connect Gateway

Dell Secure Connect Gateway contains a relative path traversal vulnerability that allows an unauthenticated remote attacker to potentially achieve remote code execution.

Executive summary

A critical relative path traversal vulnerability in Dell Secure Connect Gateway allows unauthenticated remote attackers to execute arbitrary code, posing a severe risk to system integrity.

Vulnerability

This is a relative path traversal vulnerability (CWE-23) that permits an unauthenticated attacker with network access to traverse file system directories, ultimately leading to remote code execution on the underlying host.

Business impact

The ability for an unauthenticated remote attacker to execute arbitrary code creates a significant risk of full system compromise, unauthorized data access, and potential lateral movement within the network. Given the CVSS score of 7.4, this vulnerability is classified as High severity, necessitating immediate attention to prevent unauthorized control of administrative gateway infrastructure.

Remediation

Immediate Action: Upgrade all instances of Dell Secure Connect Gateway to version 5.36.00.16 (Appliance) or 5.36.00.00 (Application) or later as specified by the vendor security advisory.

Proactive Monitoring: Review system access logs for anomalous file path requests or unauthorized execution attempts originating from external or untrusted network segments.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block directory traversal patterns (e.g., ../ sequences) targeting the gateway interface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this flaw, combined with the lack of required authentication for exploitation, demands an immediate patching cycle for all affected Dell Secure Connect Gateway deployments. Organizations should prioritize updating these systems to the vendor recommended versions to neutralize the risk of remote code execution and maintain the security posture of their management infrastructure.

More Dell CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources