ZeroHour

CVE-2026-79740

large

Hard-coded Credentials in Dell Secure Connect Gateway 5.0 Enable Information Exposure

CVSS 3.1
7.5 high
EPSS
<1%p22
Published
()
Modified
AI analysis

CVE-2026-79740 is a use of hard-coded credentials (CWE-798) in Dell Secure Connect Gateway (SCG) 5.0, affecting both the Appliance form factor (versions prior to 5.36.00.16) and the Application form factor (versions prior to 5.36.00.00). Because valid credentials are embedded in the product, an unauthenticated attacker with network access to the gateway could authenticate as though they held legitimate credentials. Successful exploitation results in exposure of sensitive information, consistent with the CVSS 3.1 score of 7.5, which rates the confidentiality impact High and integrity/availability impacts as none. Any organization running a vulnerable SCG 5.0 Appliance or Application is affected, particularly where the gateway's interface is reachable from untrusted or internet-facing networks. There is currently no evidence of exploitation in the wild: the flaw is not in CISA's KEV, no public proof-of-concept is known, and fixed versions have been released by Dell.

What to do: Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later and SCG 5.0 Application to version 5.36.00.00 or later, as directed in Dell's security advisory. Until patched, restrict the SCG interface to trusted management networks so unauthenticated remote access is not possible. Since no public PoC or in-the-wild exploitation is known, prioritize patching by first checking whether any SCG instances are internet-facing.

Affected
Dell Secure Connect Gateway 5.0 ApplianceAll versions prior to 5.36.00.16
Dell Secure Connect Gateway 5.0 ApplicationAll versions prior to 5.36.00.00
Estimated exposure
large≈10,000–100,000 enterprise deployments worldwide (estimate; only a subset likely internet-exposed) — No public installation or scan counts exist for Dell SCG, but it is deployed per enterprise customer environment alongside Dell's very large enterprise hardware install base, supporting an order-of-magnitude estimate of tens of thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.