Description
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Published: 2026-09-07
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Dell Secure Connect Gateway 5.0 stores passwords in clear text within the appliance and application, allowing a user with low privileges who has local access to read them. This flaw can lead to the disclosure of authentication credentials, compromising confidentiality and potentially enabling further attacks if those credentials are used for privileged accounts. The vulnerability is identified as CWE‑257 and rated with a CVSS score of 4.7.

Affected Systems

The issue affects Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and the Dell Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. Systems with these versions have been noted to store passwords unencrypted in configuration files or database entries; any local user with standard permissions can read those files.

Risk and Exploitability

The CVSS base score of 4.7 indicates a moderate risk, and the EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. An attacker would need local access and the ability to log on as a low‑privileged user; from there the attacker could read stored credentials. Because the flaw does not require remote exploitation or elevated privileges, the immediate threat is limited to environments where local users have higher entropy than expected.

Generated by OpenCVE AI on September 7, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell security update to 5.36.00.16 or newer for both appliance and application.
  • If an update cannot be applied immediately, restrict local user permissions to limit the ability to read configuration files.
  • Verify that stored passwords are no longer in plain text by inspecting the relevant configuration or database files.

Generated by OpenCVE AI on September 7, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell secure Connect Gateway
CPEs cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:*
cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:*
Vendors & Products Dell
Dell secure Connect Gateway

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Plaintext Password Storage in Dell Secure Connect Gateway 5.0

Mon, 07 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Weaknesses CWE-257
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Secure Connect Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-08T16:54:26.518Z

Reserved: 2026-08-25T21:04:22.135Z

Link: CVE-2026-80176

cve-icon Vulnrichment

Updated: 2026-09-08T16:37:00.587Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T17:17:25.800

Modified: 2026-09-16T20:40:54.830

Link: CVE-2026-80176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T17:30:06Z

Weaknesses
  • CWE-257

    Storing Passwords in a Recoverable Format