Dell’s Secure Connect Gateway has been found to contain three significant vulnerabilities, potentially allowing unauthorized access and control over affected systems. These flaws, if exploited, could enable attackers to execute commands remotely and gain root-level access.
Affected Versions and Urgent Updates
The vulnerabilities impact Dell Secure Connect Gateway 5.0 Appliance versions below 5.36.00.16 and Application versions below 5.36.00.00. Dell has strongly advised users to upgrade their systems immediately to safeguard against potential security breaches.
Secure Connect Gateway is pivotal for organizations connecting Dell infrastructure with support services, facilitating monitoring, diagnostics, and automated service requests. A breach in this system could provide cybercriminals with a gateway into critical enterprise environments.
Details of the Vulnerabilities
The most concerning flaw, identified as CVE-2026-80172, involves inadequate data-authenticity verification, scoring 9.8 on the CVSS scale. It allows attackers to exploit captured requests, creating administrator access tokens repeatedly without authentication.
Additionally, CVE-2026-61410, scoring 9.4, is a missing authorization vulnerability. It can let remote attackers bypass restrictions, executing unauthorized code and potentially gaining control of the system.
The third vulnerability, CVE-2026-80238, presents a privilege escalation risk, rated at 9.3. It involves the exposure of a Docker socket, enabling low-privileged users to obtain root-level access on the host system.
Mitigation and Prevention Strategies
Dell recommends immediate upgrades to Appliance version 5.36.00.16 or later and Application version 5.36.00.00 or later. Organizations should conduct thorough reviews of Secure Connect Gateway logs to detect any suspicious activities, such as unusual token generations or unauthorized remote command executions.
Security measures should include restricting network access to management interfaces to trusted networks and closely monitoring SSH access. By addressing these vulnerabilities promptly, organizations can prevent unauthorized access and potential system compromises.
The severity of these vulnerabilities underscores the importance of timely software updates and proactive security strategies in maintaining robust IT security defenses.
