Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Published: 2026-09-07
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway 5.0, with both appliance and application components, contains a hard‑coded credential weakness. The flaw allows an attacker who is not authenticated and has remote network access to log in using default administrative credentials embedded in the software. This credential misuse permits the attacker to bypass the gateway's protection mechanisms and gain administrative control over the device.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions older than 5.36.00.00 are vulnerable if the Dell DSA‑2026‑382 security update has not been applied.

Risk and Exploitability

The reported CVSS score of 6.5 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, the attack vector is remote, unauthenticated access, allowing the attacker to exploit the hard‑coded credentials. Although the exploitation probability is unknown, the impact of achieving administrative control demands that the update be applied promptly.

Generated by OpenCVE AI on September 7, 2026 at 15:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell's security update DSA-2026‑382, upgrading the appliance to version 5.36.00.16 or the application to 5.36.00.00, which removes the hard‑coded administrator credentials.
  • Restart the Secure Connect Gateway after the update to ensure the new configuration is active.
  • Limit remote management access by configuring firewall rules or access control lists to allow connections only from trusted IP addresses, reducing the attack surface while the update propagates.

Generated by OpenCVE AI on September 7, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Use of Hard‑coded Credentials Allows Remote Bypass of Protection Mechanism in Dell Secure Connect Gateway 5.0

Mon, 07 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T13:54:40.592Z

Reserved: 2026-08-25T21:04:22.134Z

Link: CVE-2026-80170

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T14:16:55.173

Modified: 2026-09-07T14:16:55.173

Link: CVE-2026-80170

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:30:06Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials