SQL Injection Vulnerability in Dell SCG 5.0 Appliance and Application
CVE-2026-79640

5.4MEDIUM

What is CVE-2026-79640?

The Dell SCG 5.0 product line is susceptible to a SQL Injection vulnerability due to improper neutralization of special elements in SQL commands. This issue can allow a low privileged attacker, remotely accessing the system, to exploit the vulnerability and gain unauthorized access to sensitive data. Affected versions include the Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. It is crucial for users to apply the latest security updates to mitigate potential risks.

Affected Version(s)

Secure Connect Gateway 5.0 - Appliance 0 < 5.36.00.16 or later

Secure Connect Gateway 5.0 - Application 0 < 5.36.00.00 or later

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.