Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information disclosure.
Published: 2026-09-09
Score: 4.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the use of a hard‑coded cryptographic key within Dell Secure Connect Gateway version 5.0, classified as CWE‑321. An attacker can potentially extract sensitive data that the gateway manages, resulting in a breach of confidentiality. The flaw does not permit direct modification or destruction of configuration, but it does create a vector for clandestine data disclosure.

Affected Systems

All Dell Secure Connect Gateway 5.0 Appliances running a version older than 5.36.00.16 and all 5.0 Application components older than 5.36.00.00 are susceptible. These are identified by Dell under the Secure Connect Gateway product line.

Risk and Exploitability

The CVSS score of 4.4 indicates a moderate severity, and the EPSS score is unavailable. The vulnerability is not currently listed in CISA’s KEV catalog. An unauthenticated attacker with remote access can potentially acquire the hard‑coded key and use it to read protected information. The lack of authentication requirements means that the attack could be performed without special credentials, though it still requires network reachability to the gateway.

Generated by OpenCVE AI on September 9, 2026 at 16:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the appliance to version 5.36.00.16 or later and the application to 5.36.00.00 or later to replace the hard‑coded key
  • Restrict or disable remote access to the Secure Connect Gateway until the patch has been applied, thereby limiting the attack surface
  • Implement continuous monitoring of gateway logs for anomalous key extraction attempts or unauthorized access patterns

Generated by OpenCVE AI on September 9, 2026 at 16:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Hard‑Coded Cryptographic Key in Dell Secure Connect Gateway 5.0 Enables Potential Information Disclosure

Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information disclosure.
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T16:09:37.598Z

Reserved: 2026-08-25T14:04:56.065Z

Link: CVE-2026-79735

cve-icon Vulnrichment

Updated: 2026-09-09T16:09:28.311Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T16:17:07.600

Modified: 2026-09-09T19:56:33.723

Link: CVE-2026-79735

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T16:45:13Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key