ZeroHour

CVE-2026-79738

large

Hard-coded Credentials in Dell Secure Connect Gateway 5.0 Expose Information

CVSS 3.1
7.5 high
EPSS
<1%p22
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 contains a use of hard-coded credentials flaw (CWE-798), meaning embedded, unchangeable credentials exist in the product. An unauthenticated attacker with network access to an affected gateway can potentially use these hard-coded credentials to authenticate to the device and retrieve information, resulting in disclosure of sensitive data; the CVSS score of 7.5 (AV:N/AC:L/PR:N/UI:N, confidentiality-only) indicates no integrity or availability impact and no privileged access is required. Both deployment forms are affected: the SCG 5.0 Appliance before version 5.36.00.16 and the SCG 5.0 Application before version 5.36.00.00. Affected organizations are those running vulnerable SCG 5.0 instances, typically enterprises using the gateway for Dell support/telemetry connectivity. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and Dell has disclosed no known exploitation.

What to do: Upgrade the SCG 5.0 Appliance to version 5.36.00.16 or later and the SCG 5.0 Application to version 5.36.00.00 or later, since patching is the only reliable fix for embedded hard-coded credentials. Until patched, restrict network access to the gateway's management interface to trusted administrative networks and avoid exposing it to the internet. Inventory SCG Appliance and Application deployments to confirm which version each runs, and watch for Dell's security advisory for any updates on exploitation.

Affected
Dell Secure Connect Gateway 5.0 ApplianceAll versions prior to 5.36.00.16
Dell Secure Connect Gateway 5.0 ApplicationAll versions prior to 5.36.00.00
Estimated exposure
largeplausibly on the order of 10,000-100,000 installations, though only a fraction are remotely reachable — SCG is Dell's standard on-prem connectivity component for enterprises using ProSupport/SupportAssist, so deployments likely number in the tens of thousands across Dell's enterprise customer base, but only sites running vulnerable 5.0…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.