ZeroHour

CVE-2026-79950

large

Hard-coded Credentials in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.5 high
EPSS
<1%p15
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0 contains a use of hard-coded credentials flaw (CWE-798), meaning a fixed, embedded credential could grant access to the affected gateway. An unauthenticated attacker with network access to the gateway could exploit it remotely, with no user interaction or special conditions required. Per the CVSS score of 7.5, the impact is limited to confidentiality: the attacker could gain information exposure, with no integrity or availability impact. Users running Dell SCG 5.0 Appliance versions prior to 5.36.00.16 or Dell SCG 5.0 Application versions prior to 5.36.00.00 are affected. There are currently no known public proof-of-concept exploits, no reports of exploitation in the wild, and the issue is not yet listed in CISA's KEV catalog.

What to do: Upgrade Dell SCG 5.0 Appliance to 5.36.00.16 or later and Dell SCG 5.0 Application to 5.36.00.00 or later. Until patched, restrict network access to the SCG interface (e.g., limit it to trusted management networks via firewall rules) and identify any instances reachable from untrusted networks or the internet, since hard-coded credentials cannot be rotated or removed through configuration.

Affected
Dell Secure Connect Gateway 5.0 Applianceall versions prior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationall versions prior to 5.36.00.00
Estimated exposure
largelikely tens of thousands of enterprise deployments worldwide, with only a subset (possibly thousands) exposed to remote attack — Dell does not publish SCG install-base figures, so this is estimated from SCG's role as Dell's standard support-connectivity gateway typically deployed once per enterprise data center or site, with most instances placed on internal…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.