{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/secure-connect-gateway-appliance--5.36.00.16/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*","cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*"],"_cs_cves":[{"cvss":5.3,"id":"CVE-2026-79941"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Secure Connect Gateway (Appliance \u003c 5.36.00.16)","Secure Connect Gateway (Application \u003c 5.36.00.00)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Dell"],"content_html":"\u003cp\u003eDell Secure Connect Gateway (SCG) versions 5.0 are affected by a critical command injection vulnerability identified as CVE-2026-79941. The flaw stems from improper neutralization of special elements used in system commands, enabling an unauthenticated remote attacker to inject malicious scripts. This vulnerability impacts both the SCG Appliance (fixed in version 5.36.00.16) and the SCG Application (fixed in version 5.36.00.00). Successful exploitation could allow an attacker to execute arbitrary commands within the context of the appliance or application, leading to a full compromise of the affected gateway. Given the administrative nature of SCG, which typically manages connectivity for hardware infrastructure, this represents a significant risk to the integrity of the network management environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability grants an unauthenticated attacker remote command execution capabilities on the affected Dell SCG appliance or application. This can lead to unauthorized access to management functions, potential exfiltration of sensitive configuration data, or lateral movement within the network from the compromised appliance. The vulnerability carries a CVSS v3.1 base score of 9.8, reflecting its high impact and ease of exploitability via remote, unauthenticated channels.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Dell Secure Connect Gateway (SCG) Appliance instances to version 5.36.00.16 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade all Dell Secure Connect Gateway (SCG) Application instances to version 5.36.00.00 or later.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the SCG web management interface to trusted administrative subnets only.\u003c/li\u003e\n\u003cli\u003eAudit network logs for anomalous HTTP requests targeting the SCG management interface that utilize shell metacharacters or encoded payloads.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T21:02:07Z","date_published":"2026-09-09T21:02:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dell-scg-command-injection/","summary":"Dell Secure Connect Gateway (SCG) contains a critical command injection vulnerability allowing unauthenticated remote attackers to perform script injection and potential unauthorized command execution.","title":"Command Injection Vulnerability in Dell Secure Connect Gateway","url":"https://feed.craftedsignal.io/briefs/2026-09-dell-scg-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Secure Connect Gateway (Appliance \u003c 5.36.00.16)","version":"https://jsonfeed.org/version/1.1"}