Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-09
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Patch Now
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 Appliance and Application contain a use‑of‑hard‑coded‑cryptographic‑key flaw. The weakness allows an attacker to bypass intended cryptographic protection, enabling unauthorized read or modification of data protected by the appliance’s gateway functions. The vulnerability is classified as CWE‑321, indicating that the fixed key is insufficiently random and secret.

Affected Systems

The flaw affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. Any installations running these earlier releases are vulnerable if not updated. The affected products are Dell Secure Connect Gateway appliances and their corresponding application components.

Risk and Exploitability

The CVSS score of 4.4 places the vulnerability in the moderate range, reflecting that remote exploitation is possible but requires an unauthenticated attacker to connect to the gateway services. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting that there is no documented active exploitation. Nonetheless, an attacker that successfully exploits the hard‑coded key could obtain unauthorized access to protected data or services.

Generated by OpenCVE AI on September 9, 2026 at 16:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Dell Secure Connect Gateway 5.0 Appliance version 5.36.00.16 or later and to Application version 5.36.00.00 or later using the Dell Security Update DSA‑2026‑382.
  • Restrict network exposure of the SCG appliance by limiting inbound traffic to the gateway services to trusted IP addresses or VPN connections.
  • Monitor gateway logs for anomalous authentication attempts and ensure any unauthorized access attempts are investigated promptly.

Generated by OpenCVE AI on September 9, 2026 at 16:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Hard‑Coded Cryptographic Key Vulnerability in Dell Secure Connect Gateway 5.0 Allowing Unauthenticated Remote Access

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T15:59:49.357Z

Reserved: 2026-08-24T17:05:26.109Z

Link: CVE-2026-78486

cve-icon Vulnrichment

Updated: 2026-09-09T15:49:38.944Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:17.170

Modified: 2026-09-09T20:08:10.910

Link: CVE-2026-78486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:45:16Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key