CVE-2026-80172
9.8Dell · Secure Connect Gateway 5.0
Dell Secure Connect Gateway 5.0 is vulnerable to an authentication bypass due to insufficient verification of data authenticity, allowing unauthenticated remote attackers to obtain administrative tokens.
Executive summary
An unauthenticated remote attacker can exploit a critical authentication vulnerability in Dell Secure Connect Gateway 5.0 to achieve full administrative access to the system.
Vulnerability
This vulnerability involves insufficient verification of data authenticity (CWE-345), where an unauthenticated attacker can replay captured requests to generate valid administrative access and refresh tokens indefinitely.
Business impact
The potential for unauthorized administrative access poses a severe risk to organizational infrastructure, as Dell Secure Connect Gateway often manages sensitive connectivity between internal assets and vendor support services. A successful compromise could lead to complete system takeover, unauthorized data exfiltration, and potential lateral movement within the network. Given the CVSS score of 9.8, this flaw represents an extreme risk to confidentiality, integrity, and availability.
Remediation
Immediate Action: Upgrade the Dell Secure Connect Gateway 5.0 Application to version 5.36.00.00 or later, or the Appliance to version 5.36.00.16 or later, as specified in the vendor security advisory.
Proactive Monitoring: Review system access logs for anomalous token generation requests or suspicious administrative activity originating from unrecognized remote IP addresses.
Compensating Controls: Implement strict network access control lists (ACLs) to restrict access to the Secure Connect Gateway interface to authorized management subnets only, effectively preventing external reachability.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical nature of this vulnerability and the ease with which an unauthenticated attacker can gain administrative privileges, immediate patching is required. Organizations should prioritize the deployment of the vendor-supplied updates to all affected gateway instances to prevent unauthorized system access.
More Dell CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section