DSA-2026-386: Security Update for Dell Secure Connect Gateway Virtual Edition Multiple Vulnerabilities
概要: Dell Secure Connect Gateway Virtual Edition remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
この記事は次に適用されます:
この記事は次には適用されません:
この記事は、特定の製品に関連付けられていません。
すべての製品パージョンがこの記事に記載されているわけではありません。
影響
Critical
詳細
| Third-party Component | CVEs | More Information |
| Apache HTTP Server | CVE-2026-23918, CVE-2026-24072, CVE-2026-28780, CVE-2026-29167, CVE-2026-29168, CVE-2026-29169, CVE-2026-29170, CVE-2026-33006, CVE-2026-33007, CVE-2026-33523, CVE-2026-33857, CVE-2026-34032, CVE-2026-34059, CVE-2026-34355, CVE-2026-34356, CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44119, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-48913, CVE-2026-49975, CVE-2026-22732, CVE-2025-67735, CVE-2026-33870, CVE-2025-46392 | https://nvd.nist.gov/vuln/search |
| containerd | CVE-2026-33186, CVE-2026-33814, CVE-2026-34986, CVE-2026-39821 | https://nvd.nist.gov/vuln/search |
| Apache Tomcat | CVE-2026-43515, CVE-2026-43512 | https://nvd.nist.gov/vuln/search |
| curl | CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, CVE-2025-15224, CVE-2026-1965, CVE-2026-3783, CVE-2026-3784, CVE-2026-3805, CVE-2026-4873, CVE-2026-5545, CVE-2026-6253, CVE-2026-6276, CVE-2026-6429, CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8927, CVE-2026-9079, CVE-2026-9080, CVE-2026-9545, CVE-2026-9547, CVE-2026-10536, CVE-2026-12064, CVE-2026-3784 | https://nvd.nist.gov/vuln/search |
| Linux Kernel | CVE-2026-64600, CVE-2026-43499, CVE-2021-47621, CVE-2026-46333, CVE-2026-43284, CVE-2026-31431, CVE-2026-23403, CVE-2026-23404, CVE-2026-23405, CVE-2026-23406, CVE-2026-23407, CVE-2026-23408, CVE-2026-23409, CVE-2026-23410, CVE-2026-23411, CVE-2026-43500 | https://nvd.nist.gov/vuln/search |
| Docker | CVE-2025-58181, CVE-2026-39984, CVE-2026-41567, CVE-2026-34040 | https://nvd.nist.gov/vuln/search |
| Spring Framework | CVE-2025-41248, CVE-2025-41232, CVE-2025-41254, CVE-2025-41249, CVE-2026-22735, CVE-2026-22737 | https://nvd.nist.gov/vuln/search |
| dracut | CVE-2026-6893, CVE-2026-15816 | https://nvd.nist.gov/vuln/search |
| Bouncy Castle Java | CVE-2025-8916 | https://nvd.nist.gov/vuln/search |
| GLib | CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58016 | https://nvd.nist.gov/vuln/search |
| glibc | CVE-2026-4046, CVE-2026-4437, CVE-2026-4438, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238 | https://nvd.nist.gov/vuln/search |
| gzip | CVE-2026-41991 | https://nvd.nist.gov/vuln/search |
| haveged | CVE-2026-41054, CVE-2026-4105 | https://nvd.nist.gov/vuln/search |
| Kerberos 5 | CVE-2026-11850, CVE-2026-40355, CVE-2026-40356 | https://nvd.nist.gov/vuln/search |
| util-linux | CVE-2025-14104, CVE-2026-3184 | https://nvd.nist.gov/vuln/search |
| libcap | CVE-2026-4878 | https://nvd.nist.gov/vuln/search |
| c-ares | CVE-2016-5180, CVE-2017-1000381, CVE-2020-8277, CVE-2021-3672, CVE-2022-4904, CVE-2023-31124, CVE-2023-31130, CVE-2023-31147, CVE-2023-32067, CVE-2024-25629 | https://nvd.nist.gov/vuln/search |
| Expat | CVE-2026-24515, CVE-2026-25210, CVE-2026-32776, CVE-2026-32777, CVE-2026-32778 | https://nvd.nist.gov/vuln/search |
| GnuTLS | CVE-2014-8564, CVE-2015-6251, CVE-2016-8610, CVE-2017-7869, CVE-2017-10790, CVE-2018-10844, CVE-2018-10845, CVE-2018-10846, CVE-2019-3829, CVE-2019-3836, CVE-2020-13777, CVE-2021-20231, CVE-2021-20232, CVE-2022-2509, CVE-2023-0361, CVE-2023-5981, CVE-2024-0553, CVE-2024-0567, CVE-2024-12243, CVE-2024-28834, CVE-2024-28835, CVE-2025-6395, CVE-2025-9820, CVE-2025-14831, CVE-2025-32988, CVE-2025-32989, CVE-2025-32990, CVE-2026-3833, CVE-2026-5260, CVE-2026-5419, CVE-2026-33845, CVE-2026-33846, CVE-2026-42009, CVE-2026-42010, CVE-2026-42011, CVE-2026-42012, CVE-2026-42013, CVE-2026-42014, CVE-2026-42015 | https://nvd.nist.gov/vuln/search |
| Graphite2 | CVE-2026-50593 | https://nvd.nist.gov/vuln/search |
| Netty | CVE-2026-33871 | https://nvd.nist.gov/vuln/search |
| Nettle | CVE-2015-8803, CVE-2015-8804, CVE-2015-8805, CVE-2016-6489, CVE-2018-16869, CVE-2021-3580, CVE-2021-20305, CVE-2023-36660 | https://nvd.nist.gov/vuln/search |
| LDB | CVE-2015-3223, CVE-2015-5330, CVE-2018-1140, CVE-2019-3824, CVE-2020-10700, CVE-2020-10730, CVE-2020-27840, CVE-2021-3670, CVE-2021-20277, CVE-2022-2031, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746, CVE-2023-0614 | https://nvd.nist.gov/vuln/search |
| XZ Utils | CVE-2026-34743 | https://nvd.nist.gov/vuln/search |
| nghttp2 | CVE-2026-27135 | https://nvd.nist.gov/vuln/search |
| OpenSSL | CVE-2026-7383, CVE-2026-9076, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789, CVE-2026-31790, CVE-2026-34180, CVE-2026-34182, CVE-2026-42766, CVE-2026-42767, CVE-2026-42770, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447, CVE-2014-3604 | https://nvd.nist.gov/vuln/search |
| libpng | CVE-2026-33416, CVE-2026-33636, CVE-2026-34757 | https://nvd.nist.gov/vuln/search |
| PostgreSQL | CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006, CVE-2026-2007, CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6575, CVE-2026-6637, CVE-2026-6638 | https://nvd.nist.gov/vuln/search |
| Python | CVE-2025-13462, CVE-2026-0864, CVE-2026-1299, CVE-2026-1502, CVE-2026-2297, CVE-2026-3276, CVE-2026-3446, CVE-2026-3479, CVE-2026-3644, CVE-2026-4224, CVE-2026-4360, CVE-2026-4519, CVE-2026-4786, CVE-2026-6019, CVE-2026-6100, CVE-2026-7210, CVE-2026-7774, CVE-2026-8328, CVE-2026-11940, CVE-2026-11972, CVE-2026-15308 | https://nvd.nist.gov/vuln/search |
| Shibboleth | CVE-2025-9943 | https://nvd.nist.gov/vuln/search |
| libsolv | CVE-2026-9149, CVE-2026-9150, CVE-2026-48863 | https://nvd.nist.gov/vuln/search |
| SQLite | CVE-2025-7709, CVE-2025-70873, CVE-2026-11822, CVE-2026-11824 | https://nvd.nist.gov/vuln/search |
| libssh | CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, CVE-2026-0968, CVE-2026-3731, CVE-2026-59843, CVE-2026-59844, CVE-2026-59845, CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59850 | https://nvd.nist.gov/vuln/search |
| libssh2 | CVE-2025-15661, CVE-2026-7598, CVE-2026-55199, CVE-2026-58050, CVE-2026-58051, CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 | https://nvd.nist.gov/vuln/search |
| SSSD | CVE-2017-12173, CVE-2018-10852, CVE-2018-16838, CVE-2019-3811, CVE-2021-3621, CVE-2023-3758, CVE-2025-11561, CVE-2026-14474, CVE-2026-14476 | https://nvd.nist.gov/vuln/search |
| systemd | CVE-2026-29111 | https://nvd.nist.gov/vuln/search |
| libxml2 | CVE-2025-8732, CVE-2025-10911, CVE-2026-0989, CVE-2026-0990, CVE-2026-0992, CVE-2026-1757, CVE-2026-11979 | https://nvd.nist.gov/vuln/search |
| libzip | CVE-2015-2331, CVE-2017-12858, CVE-2017-14107 | https://nvd.nist.gov/vuln/search |
| libzypp | CVE-2026-25707, CVE-2026-44933, CVE-2026-44941, CVE-2026-44942 | https://nvd.nist.gov/vuln/search |
| OpenSSH | CVE-2026-3497, CVE-2026-35385, CVE-2026-35388, CVE-2026-35414, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002 | https://nvd.nist.gov/vuln/search |
| Perl | CVE-2026-8376, CVE-2026-12087, CVE-2026-57432 | https://nvd.nist.gov/vuln/search |
| RPM | CVE-2026-44605 | https://nvd.nist.gov/vuln/search |
| rsync | CVE-2025-10158, CVE-2026-29518, CVE-2026-41035, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-45232 | https://nvd.nist.gov/vuln/search |
| rsyslog | CVE-2026-61548 | https://nvd.nist.gov/vuln/search |
| runc | CVE-2026-41579 | https://nvd.nist.gov/vuln/search |
| shim | CVE-2024-2312 | https://nvd.nist.gov/vuln/search |
| sudo | CVE-2026-35535 | https://nvd.nist.gov/vuln/search |
| tar | CVE-2025-45582, CVE-2026-5704 | https://nvd.nist.gov/vuln/search |
| Vim | CVE-2026-26269, CVE-2026-28417, CVE-2026-33412, CVE-2026-34714, CVE-2026-34982, CVE-2026-39881, CVE-2026-42307, CVE-2026-43961, CVE-2026-44656, CVE-2026-45130, CVE-2026-46483, CVE-2026-59856, CVE-2026-59857, CVE-2026-59858 | https://nvd.nist.gov/vuln/search |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-80247 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to unauthorized access to sensitive information, modification of protected resources, and execution of privileged operations within the appliance security context, potentially resulting in compromise of confidentiality, integrity, and availability. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80273 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to arbitrary command execution and privilege escalation, resulting in complete compromise of confidentiality, integrity, and availability of the appliance. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80283 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized disclosure of sensitive information, unauthorized modification of system resources, and execution of privileged actions that could lead to compromise of the appliance. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80287 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to system resources, disclosure of sensitive information, modification of protected configurations, and execution of privileged operations. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80291 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. A local attacker could potentially exploit this vulnerability, leading to unauthorized access to sensitive data, modification of critical resources, and disruption of appliance functionality. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80361 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to unauthorized access to sensitive information, unauthorized modification of application data, and execution of actions with elevated privileges within the appliance environment. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80367 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Out-of-bounds Write vulnerability. A local attacker could potentially exploit this vulnerability, leading to application instability, denial of service, disclosure of sensitive information, arbitrary memory modification, and potentially execution of attacker-controlled code within the affected process. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80267 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80271 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80284 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Authentication vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to exposure of sensitive data and unauthorized modification of system operations. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVE-2026-80285 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80363 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80364 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Download of Code Without Integrity Check vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to full compromise of confidentiality, integrity, and availability. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80365 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Externally-Controlled Format String vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80369 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80286 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an External Control of File Name or Path vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized file access, modification, potentially compromising confidentiality and integrity. | 7.6 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
| CVE-2026-80269 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Insecure Temporary File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
| CVE-2026-80296 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Path Traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized file access, modification, or disruption of system operations. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80297 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Path Traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized file access, modification, or disruption of system operations. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80288 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Input Validation vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information and privileged functionality. | 6.8 | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVE-2026-80290 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Race Condition vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized modification of data or service disruption. | 6.6 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80260 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 6.3 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80366 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Out-of-bounds Read vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to sensitive information exposure and application instability. | 6.2 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
| CVE-2026-80251 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Exposure of Sensitive Information vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to confidentiality impact. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-80259 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-80261 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Argument Injection vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to disclosure of sensitive information and limited integrity impact. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| CVE-2026-80293 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Argument Injection vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to disclosure of sensitive information and limited integrity impact. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| CVE-2026-80294 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-80263 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Heap-based Buffer Overflow vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to application crashes, denial of service, disclosure of sensitive information, modification of application data, and potentially arbitrary code execution within the affected process. | 5.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| CVE-2026-80249 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A local attacker with access to the appliance could potentially exploit this vulnerability, leading to information disclosure or unauthorized interaction with trusted services. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80265 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to information exposure and affecting application integrity. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80270 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an XML Injection vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized data access or manipulation. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80272 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authorization vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized actions and information exposure. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80360 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Incorrect Authorization vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to actions beyond intended permissions. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80362 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Uninitialized Variable vulnerability. A local attacker could potentially exploit this vulnerability, leading to information exposure or denial of service. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
| CVE-2026-80262 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a CRLF Injection vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to altering application-generated content and affecting system integrity. | 4.2 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80295 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a TOCTOU Race Condition vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to limited integrity impact and service instability. | 3.8 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L |
| CVE-2026-80252 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a NULL Pointer Dereference vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to denial of service. | 3.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| CVE-2026-80368 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Output Neutralization for Logs vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to server-side request forgery. | 3.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| CVE-2026-80250 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Invocation of Process Using Visible Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
| CVE-2026-80264 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Free of Memory not on the Heap vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
| CVE-2026-80266 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Removal of Sensitive Information Before Storage or Transfer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
| CVE-2026-80292 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to session theft. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-80247 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to unauthorized access to sensitive information, modification of protected resources, and execution of privileged operations within the appliance security context, potentially resulting in compromise of confidentiality, integrity, and availability. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80273 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to arbitrary command execution and privilege escalation, resulting in complete compromise of confidentiality, integrity, and availability of the appliance. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80283 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized disclosure of sensitive information, unauthorized modification of system resources, and execution of privileged actions that could lead to compromise of the appliance. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80287 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to system resources, disclosure of sensitive information, modification of protected configurations, and execution of privileged operations. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80291 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. A local attacker could potentially exploit this vulnerability, leading to unauthorized access to sensitive data, modification of critical resources, and disruption of appliance functionality. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80361 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to unauthorized access to sensitive information, unauthorized modification of application data, and execution of actions with elevated privileges within the appliance environment. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80367 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Out-of-bounds Write vulnerability. A local attacker could potentially exploit this vulnerability, leading to application instability, denial of service, disclosure of sensitive information, arbitrary memory modification, and potentially execution of attacker-controlled code within the affected process. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80267 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80271 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80284 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Authentication vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to exposure of sensitive data and unauthorized modification of system operations. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVE-2026-80285 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80363 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80364 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Download of Code Without Integrity Check vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to full compromise of confidentiality, integrity, and availability. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80365 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Externally-Controlled Format String vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80369 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80286 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an External Control of File Name or Path vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized file access, modification, potentially compromising confidentiality and integrity. | 7.6 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
| CVE-2026-80269 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Insecure Temporary File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
| CVE-2026-80296 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Path Traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized file access, modification, or disruption of system operations. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80297 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Path Traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized file access, modification, or disruption of system operations. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80288 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Input Validation vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information and privileged functionality. | 6.8 | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVE-2026-80290 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Race Condition vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized modification of data or service disruption. | 6.6 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80260 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 6.3 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80366 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Out-of-bounds Read vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to sensitive information exposure and application instability. | 6.2 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
| CVE-2026-80251 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Exposure of Sensitive Information vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to confidentiality impact. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-80259 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-80261 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Argument Injection vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to disclosure of sensitive information and limited integrity impact. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| CVE-2026-80293 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Argument Injection vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to disclosure of sensitive information and limited integrity impact. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| CVE-2026-80294 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-80263 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Heap-based Buffer Overflow vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to application crashes, denial of service, disclosure of sensitive information, modification of application data, and potentially arbitrary code execution within the affected process. | 5.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| CVE-2026-80249 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A local attacker with access to the appliance could potentially exploit this vulnerability, leading to information disclosure or unauthorized interaction with trusted services. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80265 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to information exposure and affecting application integrity. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80270 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an XML Injection vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized data access or manipulation. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80272 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authorization vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized actions and information exposure. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80360 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Incorrect Authorization vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to actions beyond intended permissions. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80362 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Uninitialized Variable vulnerability. A local attacker could potentially exploit this vulnerability, leading to information exposure or denial of service. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
| CVE-2026-80262 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a CRLF Injection vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to altering application-generated content and affecting system integrity. | 4.2 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80295 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a TOCTOU Race Condition vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to limited integrity impact and service instability. | 3.8 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L |
| CVE-2026-80252 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a NULL Pointer Dereference vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to denial of service. | 3.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| CVE-2026-80368 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Output Neutralization for Logs vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to server-side request forgery. | 3.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| CVE-2026-80250 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Invocation of Process Using Visible Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
| CVE-2026-80264 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Free of Memory not on the Heap vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
| CVE-2026-80266 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Removal of Sensitive Information Before Storage or Transfer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
| CVE-2026-80292 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to session theft. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
影響を受ける製品と修復
| Product | Affected Versions | Remediated Versions | Link |
| Dell Secure Connect Gateway Virtual Edition | Versions prior to 5.36.00.16 | Version 5.36.00.16 or later | Dell Secure Connect Gateway Virtual Edition |
| Product | Affected Versions | Remediated Versions | Link |
| Dell Secure Connect Gateway Virtual Edition | Versions prior to 5.36.00.16 | Version 5.36.00.16 or later | Dell Secure Connect Gateway Virtual Edition |
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
回避策と緩和策
None
変更履歴
| Revision | Date | Description |
| 1.0 | 2026-08-31 | Initial Release |
| 2.0 | 2026-09-01 | Formatting changes without any updates to data |
関連情報
法的免責事項
対象製品
Secure Connect Gateway, Secure Connect Gateway - Virtual Edition文書のプロパティ
文書番号: 000503504
文書の種類: Dell Security Advisory
最終更新: 01 9月 2026
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。