Dell Secure Connect Gateway Vulnerability Allows Code Execution
Summary
CERT-Bund has issued a security advisory for Dell Secure Connect Gateway, identifying a vulnerability that allows remote code execution. The advisory affects versions prior to 5.34.00.00 on Windows systems. Users are advised to apply available mitigations.
What changed
CERT-Bund has released security advisory WID-SEC-2026-0735 detailing a critical vulnerability in Dell Secure Connect Gateway software and appliance versions prior to 5.34.00.00. The vulnerability, with a CVSS Base Score of 4.7, allows authenticated remote attackers to execute arbitrary code on affected Windows systems. This advisory highlights a significant security risk for organizations utilizing this remote support software.
Organizations using Dell Secure Connect Gateway are strongly advised to review the advisory and implement the provided mitigations immediately to prevent potential exploitation. While a specific compliance deadline is not stated, prompt action is crucial to secure systems and prevent unauthorized code execution. Failure to address this vulnerability could lead to system compromise and data breaches.
What to do next
- Review CERT-Bund advisory WID-SEC-2026-0735 for affected Dell Secure Connect Gateway versions.
- Implement available mitigations for the identified code execution vulnerability.
- Update Dell Secure Connect Gateway to version 5.34.00.00 or later as soon as possible.
Source document (simplified)
[WID-SEC-2026-0735] Dell Secure Connect Gateway: Schwachstelle ermöglicht Codeausführung CVSS Base Score 4.7 (mittel) CVSS Temporal Score 4.1 (mittel) Remoteangriff ja Datum 15.03.2026 Stand 16.03.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Windows
Produktbeschreibung
Dell Secure Connect Gateway ist eine Softwarelösung, die als sicherer, zentralisierter Punkt für die Verwaltung des Fernzugriffs und des Supports für Hardware und Software von Dell Technologies dient.
Produkte
15.03.2026
- Dell Secure Connect Gateway Application <5.34.00.00
- Dell Secure Connect Gateway Appliance <5.34.00.00
Angriff
Angriff
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Dell Secure Connect Gateway ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.