Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.
Published: 2026-09-09
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 versions before 5.36.00.16 for the appliance and before 5.36.00.00 for the application contain hard‑coded credentials that can be accessed by an unauthenticated attacker with remote access. This flaw permits the attacker to authenticate as a privileged user without possessing legitimate credentials, leading to potential data exposure and other unauthorized actions. The vulnerability is classified as a Use of Hard‑Coded Credentials deficiency (CWE‑798).

Affected Systems

The affected products are Dell Secure Connect Gateway 5.0 Appliance and Dell Secure Connect Gateway 5.0 Application, with all versions prior to 5.36.00.16 for appliance and prior to 5.36.00.00 for application being vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high risk to confidentiality and possibly integrity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attacker can exploit the vulnerability over a remote connection without authentication, making the attack vector readily feasible. Exploitation requires only network access to the SCG services; no local privileges or insider knowledge are needed, which increases the likelihood of compromise.

Generated by OpenCVE AI on September 9, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Dell security update by installing version 5.36.00.16 or later on the SCG appliance and version 5.36.00.00 or later on the SCG application.
  • If a patch is not immediately deployable, restrict external network access to the SCG services using firewall rules or VLAN segmentation to limit exposure.
  • After patching, verify that no hard‑coded or default credentials remain in configuration files and change any that still exist to strong, unique passwords.
  • Monitor logs for anomalous authentication attempts and conduct regular vulnerability scans to confirm that the hard‑coded credential issue has been resolved.

Generated by OpenCVE AI on September 9, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Use of Hard-Coded Credentials in Dell Secure Connect Gateway 5.0 Allows Remote Information Exposure
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T14:33:27.220Z

Reserved: 2026-08-25T15:04:54.601Z

Link: CVE-2026-79950

cve-icon Vulnrichment

Updated: 2026-09-09T14:33:13.549Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T14:17:18.170

Modified: 2026-09-09T15:38:39.083

Link: CVE-2026-79950

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T15:15:04Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials