Improper Neutralization of XSS Syntax in Dell SCG 5.0 Appliance
CVE-2026-79946

5.3MEDIUM

What is CVE-2026-79946?

The Dell SCG 5.0 Appliance and Application prior to specified versions are susceptible to an improper neutralization of alternate XSS syntax vulnerability. This security flaw allows an unauthenticated remote attacker to inject malicious scripts into the applications. If exploited, it could lead to unauthorized access to sensitive information or manipulation of application behavior, posing significant risks to users and systems.

Affected Version(s)

Secure Connect Gateway 5.0 - Appliance 0 < 5.36.00.16 or later

Secure Connect Gateway 5.0 - Application 0 < 5.36.00.00 or later

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.