Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Published: 2026-09-07
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use of a hard‑coded cryptographic key in Dell Secure Connect Gateway 5.0 Appliance and Application. A low privileged attacker with local access can read or abuse this key, potentially exposing confidential data stored or transmitted by the gateway. The impact is the disclosure of sensitive information, as the attacker can reconstruct or decrypt data that should remain protected. No remote execution or privilege escalation is described, but the confidentiality loss may compromise broader network assets if the gateway is part of key infrastructure.

Affected Systems

Dell Secure Connect Gateway Appliance versions older than 5.36.00.16 and Dell Secure Connect Gateway Application versions older than 5.36.00.00 are affected. Only the specified appliance and application product lines are impacted; other Dell Secure Connect Gateway deployments with newer versions are not affected according to the CNA data.

Risk and Exploitability

The CVSS score of 5.5 indicates a medium risk level. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation at present. The attack requires local, low‑privileged access, so the likelihood of exploitation depends on the local security posture. Because the weakness involves a hard‑coded key (CWE‑321), if an attacker gains local access they could use the key to decrypt traffic or other protected data, leading to potential downstream compromise if other assets rely on that key.

Generated by OpenCVE AI on September 7, 2026 at 15:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Security Update for Secure Connect Gateway 5.0 that upgrades the Appliance to at least 5.36.00.16 and the Application to at least 5.36.00.00, removing the hard‑coded key; deploy the update to all affected devices as a priority.
  • Configure the appliance to enforce strict local access controls, such as disabling console login and limiting SSH access to privileged accounts only, to reduce the risk of low‑privileged local attackers.
  • If an immediate update is not possible, isolate the appliance from untrusted networks and monitor its logs for anomalous attempts to read or use the hard‑coded key, then plan a key rotation or isolation strategy to mitigate potential exposure.

Generated by OpenCVE AI on September 7, 2026 at 15:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Dell Secure Connect Gateway Use of Hard‑coded Cryptographic Key Leading to Information Disclosure

Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T14:12:33.707Z

Reserved: 2026-08-25T18:04:39.714Z

Link: CVE-2026-80057

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T15:17:32.397

Modified: 2026-09-07T15:17:32.397

Link: CVE-2026-80057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:45:17Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key