Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Dell has disclosed three critical vulnerabilities in its Secure Connect Gateway 5.0 platform that could allow attackers to gain unauthorized access, execute commands remotely, and obtain root-level control of affected systems.

The flaws affect Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00.

Dell has urged customers to upgrade as soon as possible because the issues could expose support-management infrastructure to serious compromise.

Organizations use Secure Connect Gateway to connect Dell infrastructure with Dell support services for monitoring, diagnostics, and automated service requests. A successful attack on the platform could therefore give an attacker a foothold in environments containing critical enterprise infrastructure.

The most severe issue, tracked as CVE-2026-80172, is an insufficient data-authenticity verification flaw with a CVSS score of 9.8. An unauthenticated remote attacker could exploit captured requests to create administrator access tokens and refresh tokens repeatedly.

Dell Secure Connect Gateway Vulnerabilities

According to Dell’s advisory, the affected implementation does not enforce nonce validation or a request time limit. This means an attacker who captures a valid request may be able to replay it indefinitely. The weakness could enable persistent unauthorized administrative access without requiring valid login credentials.

A second vulnerability, CVE-2026-61410, is a missing authorization issue rated 9.4 on the CVSS scale. An unauthenticated attacker with remote access could send a specially crafted request to the Secure Connect Gateway application and bypass intended restrictions on code execution.

Successful exploitation could allow remote command execution on the affected system. Attackers could use this access to run malicious commands, collect sensitive data, alter configurations, deploy persistence mechanisms, or move laterally across the network.

The third flaw, CVE-2026-80238, has a CVSS score of 9.3 and involves execution with unnecessary privileges. The vulnerability requires local access, but it could allow a low-privileged operator with SSH access to the Secure Connect Gateway host to gain root-level privileges.

The issue stems from an exposed Docker socket. A low-privileged user could leverage the socket to access the host environment without requiring a password.

Dell also warned that an attacker who compromises a service inside the orchestrator container could access the same Docker socket, escape the container boundary, and take control of the underlying host. Together, the vulnerabilities create multiple paths to compromise affected Secure Connect Gateway deployments fully.

An attacker could potentially obtain administrator tokens through request replay, execute commands remotely through authorization bypass, or escalate privileges through the Docker socket exposure. Organizations using Dell Secure Connect Gateway should identify affected appliance and application deployments immediately.

Administrators should upgrade Appliance installations to version 5.36.00.16 or later and Application installations to version 5.36.00.00 or later.

Security teams should also review Secure Connect Gateway logs for suspicious token-generation activity, unusual API requests, unexpected remote command execution, and unauthorized SSH sessions.

Restrict network access to management interfaces to trusted administrative networks, and limit and monitor SSH access. Dell classified all three issues as critical and recommends immediate remediation to prevent unauthorized access and possible host-level compromise.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access appeared first on Cyber Security News.