CVE-2026-61409

Summary

Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.

Affected Software

VendorProductVersion RangeStatus
DellSecure Connect Gateway (SCG) 5.0 Application0 < 5.36.00.00 or lateraffected
DellSecure Connect Gateway 5.0 - Appliance0 < 5.36.00.16 or lateraffected

Weaknesses

  • CWE-78: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

References