Database/Control plane, storage & DevOps
Dell Secure Connect Gateway: exposed Docker socket gives a local user or container host root
Impact
SCG is the appliance that carries support telemetry and remote connectivity for a Dell server, storage and networking fleet, so it sits inside the management path of the hardware a GPU site runs on. The Docker socket is reachable from the appliance host without root and from inside the orchestrator container, so an operator holding only an SSH account escalates to root on the appliance, and anything that compromises a service in the container escapes the container boundary and lands on the host. Dell rates it 9.3 with a scope change. Whoever owns the appliance owns its stored fleet credentials and its outbound support channel.
Who can reach it
Local access to the SCG host - Dell describes a low-privileged operator with SSH needing no password for the escalation - or code execution inside the orchestrator container. No prior root required.
What to do
Upgrade the SCG 5.0 Appliance to 5.36.00.16 or later and the SCG 5.0 Application to 5.36.00.00 or later, per DSA-2026-382. This is a virtual-appliance upgrade, so plan for the gateway to be offline during it - support telemetry and remote sessions stop until it is back. Until then, audit who holds shell accounts on the appliance, since that is the whole precondition.
References
Related entries
- MinIO (OIDC authentication): JWT algorithm confusion in the OIDC login path lets an attacker present a token the serverCVE-2026-33322 · MinIO (OIDC authentication)Critical
- rclone (rc API, options/set): options/set is exposed pre-authentication and can rewrite the running instance's authCVE-2026-41176 · rclone (rc API, options/set)Critical
- rclone (rc API, operations/fsinfo): operations/fsinfo is reachable without authentication and accepts anCVE-2026-41179 · rclone (rc API, operations/fsinfo)Critical
- Moxa NPort W2150A / W2250A wireless device server: The device ships with an empty default password, so anyone who canCVE-2017-16727 · Moxa NPort W2150A / W2250A wireless device serverCritical
- Brocade Fabric OS (proxy service information disclosure): Unauthenticated remote attackers can obtain sensitiveCVE-2018-6440 · Brocade Fabric OS (proxy service information disclosure)Critical
- IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1: Unauthorized access to user data, or injection ofCVE-2020-4926 · IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.