Impact
Dell Secure Connect Gateway 5.0 appliances and applications before versions 5.36.00.16 (Appliance) and 5.36.00.00 (Application) contain a use of hard‑coded credentials flaw. An attacker who can reach the system remotely can authenticate using fixed credentials embedded in the software, allowing the attacker to gain access to network‑level information and potentially sensitive configuration data. The weakness is classified as CWE‑798 and can lead to unauthorized data discovery and disclosure.
Affected Systems
Vulnerable are Dell Secure Connect Gateway 5.0 Appliance and Application. The affected ranges are all Appliance builds prior to 5.36.00.16 and all Application builds prior to 5.36.00.00.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. Because the vulnerability is exploitable by unauthenticated remote users, the likelihood of attack is non‑negligible, even though a formal EPSS score is not available. The vulnerability is not in the CISA KEV catalog. An unauthenticated attacker with network access to the gateway could use the embedded credentials to log in, read configuration, and potentially pivot to other systems on the network.
OpenCVE Enrichment