CVE-2026-79950
largeHard-coded Credentials in Dell Secure Connect Gateway 5.0
Dell Secure Connect Gateway (SCG) 5.0 contains a use of hard-coded credentials flaw (CWE-798), meaning a fixed, embedded credential could grant access to the affected gateway. An unauthenticated attacker with network access to the gateway could exploit it remotely, with no user interaction or special conditions required. Per the CVSS score of 7.5, the impact is limited to confidentiality: the attacker could gain information exposure, with no integrity or availability impact. Users running Dell SCG 5.0 Appliance versions prior to 5.36.00.16 or Dell SCG 5.0 Application versions prior to 5.36.00.00 are affected. There are currently no known public proof-of-concept exploits, no reports of exploitation in the wild, and the issue is not yet listed in CISA's KEV catalog.
What to do: Upgrade Dell SCG 5.0 Appliance to 5.36.00.16 or later and Dell SCG 5.0 Application to 5.36.00.00 or later. Until patched, restrict network access to the SCG interface (e.g., limit it to trusted management networks via firewall rules) and identify any instances reachable from untrusted networks or the internet, since hard-coded credentials cannot be rotated or removed through configuration.
| Dell Secure Connect Gateway 5.0 Appliance | all versions prior to 5.36.00.16 |
| Dell Secure Connect Gateway 5.0 Application | all versions prior to 5.36.00.00 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.
- Vendors
- dell
- Products
- secure connect gateway
- Weakness
- CWE-798
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.