Insufficient Verification of Data Authenticity in Dell SCG Products
CVE-2026-80172

9.8CRITICAL

What is CVE-2026-80172?

The Dell SCG 5.0 Appliance and Application prior to specified versions contain a vulnerability due to insufficient verification of data authenticity. This flaw allows an unauthenticated attacker with remote access to exploit the system. By reusing a captured request, attackers can gain unauthorized ADMIN access and refresh tokens repeatedly without nonce validation or a time limit. Dell advises users to upgrade their systems promptly to mitigate this security risk.

Affected Version(s)

Secure Connect Gateway 5.0 - Appliance 0 < 5.36.00.16 or later

Secure Connect Gateway 5.0 - Application 0 < 5.36.00.00 or later

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.