Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Published: 2026-09-07
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized remote access due to hard‑coded credentials
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a use of hard‑coded credentials in Dell Secure Connect Gateway 5.0, allowing an unauthenticated attacker with remote access to obtain unauthorized access. This flaw can potentially grant administrative privileges to the attacker, leading to full control of the device and any networks it connects to. The flaw is present in appliances prior to version 5.36.00.16 and applications prior to 5.36.00.00.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance models running a version older than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application models running a version older than 5.36.00.00 are affected. Only these product lines are vulnerable to the hard‑coded credential issue.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity. Although the EPSS score is not provided, the lack of a listed KEV status means no known public exploits have been documented yet. Nonetheless, the vulnerability allows unauthenticated remote attackers to potentially compromise the appliance or application, making this a critical concern for systems exposed to external networks. An attacker could exploit the flaw by connecting remotely and using the default credentials, leading to unauthorized control of the gateway.

Generated by OpenCVE AI on September 7, 2026 at 14:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell security update to bring the appliance to at least version 5.36.00.16 and the application to at least version 5.36.00.00, which removes the hard‑coded credential flaw.
  • Ensure that the SCG management interfaces are protected by network segmentation or VPN access and are not exposed to the public internet.
  • Monitor authentication logs for unusual or repeated failed login attempts and enable alerting for suspicious activity.

Generated by OpenCVE AI on September 7, 2026 at 14:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell secure Connect Gateway

Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application
Vendors & Products Dell
Dell secure Connect Gateway Appliance
Dell secure Connect Gateway Application

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Use of Hard‑coded Credentials in Dell Secure Connect Gateway 5.0 Enabling Unauthorized Remote Access

Mon, 07 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Dell Secure Connect Gateway Secure Connect Gateway Appliance Secure Connect Gateway Application
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-08T13:57:19.659Z

Reserved: 2026-08-25T20:04:12.994Z

Link: CVE-2026-80134

cve-icon Vulnrichment

Updated: 2026-09-08T13:57:10.927Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T13:20:38.923

Modified: 2026-09-11T21:25:15.237

Link: CVE-2026-80134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:37:16Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials