Impact
Dell Secure Connect Gateway 5.0, with both appliance and application components, contains a hard‑coded credential weakness. The flaw allows an attacker who is not authenticated and has remote network access to log in using default administrative credentials embedded in the software. This credential misuse permits the attacker to bypass the gateway's protection mechanisms and gain administrative control over the device.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions older than 5.36.00.00 are vulnerable if the Dell DSA‑2026‑382 security update has not been applied.
Risk and Exploitability
The reported CVSS score of 6.5 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, the attack vector is remote, unauthenticated access, allowing the attacker to exploit the hard‑coded credentials. Although the exploitation probability is unknown, the impact of achieving administrative control demands that the update be applied promptly.
OpenCVE Enrichment