Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
Published: 2026-09-09
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Update
AI Analysis

Impact

The vulnerability is an insufficient entropy issue in the pseudorandom number generator, allowing a local attacker with low privileges to increase their privileges.

Affected Systems

Dell Secure Connect Gateway 5.0 Appliance, versions prior to 5.36.00.16, and Dell Secure Connect Gateway 5.0 Application, versions prior to 5.36.00.00, are affected.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate risk. The EPSS score is not available, and the vulnerability is not listed in the KEV catalog. Based on the description, a local user or process with limited privileges may exploit the low-entropy PRNG to elevate privileges. Attackers would need local access and can achieve a higher level of control on the affected appliance or application.

Generated by OpenCVE AI on September 9, 2026 at 12:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell Secure Connect Gateway 5.0 Security Update DSA-2026-382 to reach at least version 5.36.00.16 on Appliance and 5.36.00.00 on Application.
  • Restart Secure Connect Gateway services so the updated PRNG settings take effect.
  • Set up monitoring of system logs for local privilege escalation events to detect any abuse of the vulnerability.

Generated by OpenCVE AI on September 9, 2026 at 12:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Insufficient Entropy in PRNG Leading to Local Privilege Escalation in Dell Secure Connect Gateway 5.0

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
Weaknesses CWE-331
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-09T16:01:25.832Z

Reserved: 2026-08-25T21:04:22.134Z

Link: CVE-2026-80171

cve-icon Vulnrichment

Updated: 2026-09-09T15:49:43.324Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T12:17:14.907

Modified: 2026-09-09T18:58:33.943

Link: CVE-2026-80171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:30:16Z

Weaknesses