{"id":"CVE-2026-79946","title":"Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability","summary":"Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access coul…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-87"],"vendor":"dell","product":"secure_connect_gateway","affected":["secure_connect_gateway < 5.36.00.00","secure_connect_gateway < 5.36.00.16"],"patched":["secure_connect_gateway 5.36.00.16"],"published":"2026-09-09","updated":"2026-09-14","sourceUpdated":"2026-09-14T14:17:11.640","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79946","references":[{"url":"https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities","label":"security_alert@emc.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-14T13:36:26.428044Z"},"epss":0.00211,"epssPercentile":0.11693,"ingestedAt":"2026-09-14T15:23:07.419Z","slug":"CVE-2026-79946","body":"## Overview\n\nDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.\n\n## Affected\n\n- `secure_connect_gateway < 5.36.00.00`\n- `secure_connect_gateway < 5.36.00.16`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `secure_connect_gateway 5.36.00.16`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}