CVE-2026-61409: OS Command Injection
Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Secure Connect Gateway (SCG) 5.0 Applicationto a version that resolves this vulnerability.Fixed in 5.36.00.00
Event History
Frequently Asked Questions
Which deployments are affected?
Dell Secure Connect Gateway (SCG) 5.0 Application versions earlier than 5.36.00.00 are affected.
Does exploitation require an account or user interaction?
No. The vulnerability can potentially be exploited by an unauthenticated attacker with remote access, and the supplied vector indicates no user interaction is required.
What could an attacker gain from successful exploitation?
Successful exploitation could lead to remote command execution. The stated impact includes low confidentiality, integrity, and availability effects.