CVE-2026-79740
largeHard-coded Credentials in Dell Secure Connect Gateway 5.0 Enable Information Exposure
CVE-2026-79740 is a use of hard-coded credentials (CWE-798) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance form factor (versions prior to 5.36.00.16) and the Application form factor (versions prior to 5.36.00.00). Because valid credentials are embedded in the product, an unauthenticated attacker with network access to the gateway could authenticate as though they held legitimate credentials. Successful exploitation results in exposure of sensitive information, consistent with the CVSS 3.1 score of 7.5, which rates the confidentiality impact High and integrity/availability impacts as none. Any organization running a vulnerable SCG 5.0 Appliance or Application is affected, particularly where the gateway's interface is reachable from untrusted or internet-facing networks. There is currently no evidence of exploitation in the wild: the flaw is not in CISA's KEV, no public proof-of-concept is known, and fixed versions have been released by Dell.
What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later, as directed in Dell's security advisory. Until patched, restrict the SCG interface to trusted management networks so unauthenticated remote access is not possible. Since no public PoC or in-the-wild exploitation is known, prioritize patching by first checking whether any SCG instances are internet-facing.
| Dell Secure Connect Gateway 5.0 Appliance | All versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | All versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-798
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.