PatchSiren cyber security CVE debrief
CVE-2026-80130 Dell CVE debrief
A Relative Path Traversal vulnerability exists in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to remote execution. The vulnerability allows attackers to traverse directories, potentially leading to unauthorized access and execution of malicious code. Defenders should assess exposure and verify remote access controls to mitigate potential risks.
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
Defenders responsible for Dell SCG 5.0 Appliance and Application deployments should assess exposure and verify remote access controls. Additionally, security teams, vulnerability management teams, and operators managing these systems should be aware of the potential risks and take necessary precautions to mitigate them. They should review system versions, assess remote access configurations, and monitor for potential exploitation attempts to ensure the of
Why it matters
Defenders should prioritize verifying exposure and assessing remote access controls for Dell SCG 5.0 Appliance and Application deployments due to a Relative Path Traversal vulnerability.
- Remote code execution is possible for low-privileged attackers with remote access
- Defenders must verify exposure and assess remote access controls
Technical summary
The vulnerability exists in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to remote execution. The vulnerability is caused by improper handling of directory traversal, allowing attackers to access sensitive files and directories. Defenders should prioritize verifying exposure and assessing remote access controls, especially for low-privileged users, to mitigate potential risks.
Defensive priority
Defenders should prioritize verifying exposure and assessing remote access controls, especially for low-privileged users.
Recommended defensive actions
- Verify exposure by checking system versions and remote access configurations
- Assess and limit remote access for low-privileged users
- Monitor for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and remediation is limited. The Dell SCG 5.0 Appliance and Application versions prior to 5.36.00.16 and 5.36.00.00 respectively are confirmed to be vulnerable. However, specific details about the vulnerability's impact and exploitation are not extensively documented in the available sources. Defenders should verify system versions, assess remote access configurations, and monitor for potential exploitation attempts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80130 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80130
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80130 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80130
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.