---
id: CVE-2026-78484
title: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Neutralization
  of Special Elements used in an OS Command ('OS Command Injection')
  vulnerability
summary: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Neutralization
  of Special Elements used in an OS Command ('OS Command Injection')
  vulnerability. A low pr…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-77
vendor: Dell
product: Secure Connect Gateway 5.0 - Application
affected:
  - secure_connect_gateway_5.0_-_application < 5.36.00.00 or later
  - secure_connect_gateway_5.0_-_appliance < 5.36.00.16 or later
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T03:56:16.298911Z'
published: '2026-09-09'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T13:06:07.695Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-78484'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities
tags:
  - cve.org
epss: 0.0182
epssPercentile: 0.77459
ingestedAt: '2026-09-11T16:45:47.910Z'
---

## Overview

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.

## Affected

- `secure_connect_gateway_5.0_-_application < 5.36.00.00 or later`
- `secure_connect_gateway_5.0_-_appliance < 5.36.00.16 or later`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
