Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Published: 2026-09-09
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the use of hard‑coded cryptographic keys in Dell Secure Connect Gateway 5.0. This weakness is categorized as CWE‑321 and allows a low‑privileged attacker with remote access to bypass protection mechanisms, potentially enabling unauthorized actions or data access.

Affected Systems

Affected are Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. These versions do not include the key‑management updates required to eliminate hard‑coded keys.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, indicating moderate risk. EPSS is not available, and the lack of listing in CISA KEV suggests no public exploit has been documented yet. Attackers would need remote reach to the gateway and could leverage the weak key to circumvent authentication or other protection mechanisms. The risk is moderate but non‑negligible, especially in environments with low‑privileged users having network access to the appliance.

Generated by OpenCVE AI on September 9, 2026 at 13:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Dell SCG 5.0 update to version 5.36.00.16 for the Appliance or 5.36.00.00 for the Application to eliminate the hard‑coded key.
  • Configure the gateway to use securely stored cryptographic keys rather than hard‑coded values, following Dell’s guidance on key management.
  • Restrict remote management access to authorized IP ranges or VPN only to reduce exposure of the vulnerable components.
  • Monitor authentication and configuration logs for suspicious activity following the update.

Generated by OpenCVE AI on September 9, 2026 at 13:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Use of Hard‑coded Cryptographic Key Allows Protection Bypass in Dell Secure Connect Gateway

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T12:39:47.807Z

Reserved: 2026-08-24T17:05:26.109Z

Link: CVE-2026-78481

cve-icon Vulnrichment

Updated: 2026-09-09T12:36:53.171Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T12:17:13.313

Modified: 2026-09-09T15:38:39.083

Link: CVE-2026-78481

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T13:30:10Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key