External risk intelligence

Dell SCG Insufficient Data Authenticity Vulnerability Allows Unauthorized Admin Access

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-80172

The Dell Secure Connect Gateway (SCG) is an appliance designed to manage connectivity between an organization's infrastructure and the vendor for support and telemetry. Such gateway and management appliances are commonly deployed in network configurations that provide the service with the necessary external connectivity to function, making them reachable as edge or gateway services.

Dell Secure Connect Gateway

before 5.36.00.00before 5.36.00.16

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical security vulnerability impacting Dell Secure Connect Gateway appliances and applications. The issue allows unauthenticated remote attackers to gain unauthorized administrative access by repeatedly reusing captured requests, potentially enabling sustained system compromise. Dell recommends immediate upgrades to mitigate this risk.

  • Unauthenticated access granted via request replay.
  • Confirms management gateway exposure risks.
  • Prioritize assessment of this gateway vulnerability.

Attack Path

How an attacker could exploit the issue

An attacker could reach the Dell Secure Connect Gateway appliance or application with remote access. By reusing captured requests without checks, the attacker can gain administrative access and refresh tokens. This allows for ongoing unauthorized control of the system.

  • Requires remote access, no authentication needed.
  • Reusing captured requests triggers the vulnerability.
  • Results in unauthorized administrative access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to gain administrative control of the Dell SCG appliance by repeatedly reusing captured requests. This could lead to unauthorized access and manipulation of the appliance's functions.

  • Administrative access to the appliance.
  • Reusing captured network requests.
  • Unauthorized system control.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for Dell Secure Connect Gateway appliances and applications should prioritize identifying all deployed instances. Confirming reachability and business criticality is essential to assess risk and identify the accountable owner for remediation planning.

  • Application or Infrastructure owners
  • Verify external reachability and business impact.
  • Plan and execute vendor-provided updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Dell Secure Connect Gateway?

Dell Secure Connect Gateway (SCG) is a software appliance and application designed to handle connectivity between an organization's IT infrastructure and Dell support services. It acts as a bridge for telemetry data and remote management, ensuring that devices can communicate securely with the vendor for maintenance and support purposes.

What does CVE-2026-80172 mean?

This CVE identifies a flaw involving Insufficient Verification of Data Authenticity (CWE-345). Essentially, the software fails to properly check if incoming requests are legitimate or authentic. Because it does not validate unique request identifiers or timestamps, an attacker can capture and replay valid requests to trick the system into granting unauthorized administrative privileges.

How can an attacker trigger this vulnerability?

An unauthenticated attacker with remote network access can trigger this by replaying previously captured requests to the gateway. The system accepts these reused requests as if they were new, granting admin access without requiring original credentials. Notably, standard, single-use, or correctly timestamped requests that the system expects would not follow this replay pattern, but here the system lacks the necessary validation to reject the reused ones.

Is my Dell SCG appliance at risk?

Your risk depends on network placement. According to Halo Surface Signal, Dell Secure Connect Gateway appliances are frequently deployed at the network edge to maintain required connectivity to the vendor. If your instance is accessible from the internet, it is at higher risk because attackers do not need prior authentication to attempt this exploit remotely.

What should I do to secure my environment?

You should immediately identify all deployed instances of Dell SCG within your infrastructure. Once located, verify their network exposure and business impact. The primary action is to apply the security updates provided by Dell, which resolve the authentication flaw, as upgrading to the latest versions is the only way to prevent unauthorized administrative access.

References