---
id: CVE-2026-80055
title: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Neutralization
  of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability
summary: >-
  Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0
  Application versions prior to 5.36.00.00, contains an Improper Neutralization
  of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. An
  unauthentic…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-90
vendor: dell
product: secure_connect_gateway
affected:
  - secure_connect_gateway < 5.36.00.00
  - secure_connect_gateway < 5.36.00.16
patched:
  - secure_connect_gateway 5.36.00.16
published: '2026-09-09'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:16:52.603'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80055'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities
    label: security_alert@emc.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T13:02:00.526257Z'
ingestedAt: '2026-09-13T14:51:19.075Z'
epss: 0.00337
epssPercentile: 0.24277
---

## Overview

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.

## Affected

- `secure_connect_gateway < 5.36.00.00`
- `secure_connect_gateway < 5.36.00.16`

## Remediation

Upgrade past the affected range:

- `secure_connect_gateway 5.36.00.16`
