Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Published: 2026-09-07
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 stores passwords in clear text within the appliance and application, allowing a user with low privileges who has local access to read them. This flaw can lead to the disclosure of authentication credentials, compromising confidentiality and potentially enabling further attacks if those credentials are used for privileged accounts. The vulnerability is identified as CWE‑257 and rated with a CVSS score of 4.7.

Affected Systems

The issue affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and the Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. Systems with these versions have been noted to store passwords unencrypted in configuration files or database entries; any local user with standard permissions can read those files.

Risk and Exploitability

The CVSS base score of 4.7 indicates a moderate risk, and the EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. An attacker would need local access and the ability to log on as a low‑privileged user; from there the attacker could read stored credentials. Because the flaw does not require remote exploitation or elevated privileges, the immediate threat is limited to environments where local users have higher entropy than expected.

Generated by OpenCVE AI on September 7, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell security update to 5.36.00.16 or newer for both appliance and application.
  • If an update cannot be applied immediately, restrict local user permissions to limit the ability to read configuration files.
  • Verify that stored passwords are no longer in plain text by inspecting the relevant configuration or database files.

Generated by OpenCVE AI on September 7, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Plaintext Password Storage in Dell Secure Connect Gateway 5.0

Mon, 07 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Weaknesses CWE-257
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-07T16:31:22.573Z

Reserved: 2026-08-25T21:04:22.135Z

Link: CVE-2026-80176

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T17:17:25.800

Modified: 2026-09-07T17:17:25.800

Link: CVE-2026-80176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T17:30:06Z

Weaknesses
  • CWE-257

    Storing Passwords in a Recoverable Format