CVE-2026-79972: SQL Injection
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell SCG 5.0 Applianceto a version that resolves this vulnerability.Fixed in 5.36.00.16 - Upgrade
Upgrade
Dell SCG 5.0 Applicationto a version that resolves this vulnerability.Fixed in 5.36.00.00
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs remote access and high privileges. The provided information does not indicate that unauthenticated or low-privileged users can exploit it.
Which deployments need to be updated?
Dell SCG 5.0 Appliance deployments prior to 5.36.00.16 and Dell SCG 5.0 Application deployments prior to 5.36.00.00 are affected.
What could successful exploitation allow?
Successful exploitation could lead to unauthorized access. The severity vector indicates potential high impact to confidentiality, integrity, and availability.